Nextcloud is an open source content collaboration platform. From versions 5.5.13 to before 5.5.17, and 6.2.0 to before 6.2.3, an authenticated user can enumerate users on the same Nextcloud instance by using the Calendar app's endpoint for suggesting attendees. The sharing restrictions, applied to other endpoints, were not effective here. This issue has been patched in versions 5.5.17 and 6.2.3.
References
| Link | Resource |
|---|---|
| https://github.com/nextcloud/calendar/issues/7971 | Exploit Issue Tracking Patch |
| https://github.com/nextcloud/calendar/pull/8197 | Issue Tracking Patch |
| https://github.com/nextcloud/security-advisories/security/advisories/GHSA-r697-74m9-gvf2 | Mitigation Vendor Advisory |
| https://hackerone.com/reports/3540663 | Permissions Required |
Configurations
Configuration 1 (hide)
|
History
03 Jun 2026, 20:35
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Nextcloud calendar
Nextcloud |
|
| References | () https://github.com/nextcloud/calendar/issues/7971 - Exploit, Issue Tracking, Patch | |
| References | () https://github.com/nextcloud/calendar/pull/8197 - Issue Tracking, Patch | |
| References | () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-r697-74m9-gvf2 - Mitigation, Vendor Advisory | |
| References | () https://hackerone.com/reports/3540663 - Permissions Required | |
| CWE | NVD-CWE-noinfo | |
| CPE | cpe:2.3:a:nextcloud:calendar:*:*:*:*:*:*:*:* |
01 Jun 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-01 19:16
Updated : 2026-06-03 20:35
NVD link : CVE-2026-45286
Mitre link : CVE-2026-45286
CVE.ORG link : CVE-2026-45286
JSON object : View
Products Affected
nextcloud
- calendar
CWE
