Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, with the knowledge of other users’ principal URL an attacker could possibly send a request to gain full access to their calendar. Therefore, the attacker must be an authenticated user. This is because of improper authorization controls in the backend of the calendar. If the attacker had access to the calendar, they would be able to view and modify it. It is recommended that the Nextcloud Server is upgraded to 33.0.3 or 32.0.9. It is recommended that the Nextcloud Enterprise Server is upgraded to 33.0.3, 32.0.9, 31.0.14.5, 30.0.17.9, 29.0.16.16, 28.0.14.17, 27.1.11.26, 26.0.13.26, 25.0.13.29, 24.0.12.34, 23.0.12.35, 22.2.10.39, or 21.0.9.23
References
| Link | Resource |
|---|---|
| https://github.com/nextcloud/security-advisories/security/advisories/GHSA-hrrv-mp25-26vv | Mitigation Vendor Advisory |
| https://github.com/nextcloud/server/pull/59962 | Issue Tracking Patch |
| https://hackerone.com/reports/3545964 | Permissions Required |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
03 Jun 2026, 17:11
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-hrrv-mp25-26vv - Mitigation, Vendor Advisory | |
| References | () https://github.com/nextcloud/server/pull/59962 - Issue Tracking, Patch | |
| References | () https://hackerone.com/reports/3545964 - Permissions Required | |
| First Time |
Nextcloud
Nextcloud nextcloud Server |
|
| CPE | cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:* cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:* |
01 Jun 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-01 19:16
Updated : 2026-06-03 17:11
NVD link : CVE-2026-45281
Mitre link : CVE-2026-45281
CVE.ORG link : CVE-2026-45281
JSON object : View
Products Affected
nextcloud
- nextcloud_server
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
