CVE-2026-45286 Details
Description
Nextcloud is an open source content collaboration platform. From versions 5.5.13 to before 5.5.17, and 6.2.0 to before 6.2.3, an authenticated user can enumerate users on the same Nextcloud instance by using the Calendar app's endpoint for suggesting attendees. The sharing restrictions, applied to other endpoints, were not effective here. This issue has been patched in versions 5.5.17 and 6.2.3.
A data protection vulnerability exists in the Nextcloud Calendar app, specifically in versions 5.5.13 prior to 5.5.17 and 6.2.0 prior to 6.2.3. The issue allows authenticated users to enumerate all users on the same Nextcloud instance through the calendar's attendee suggestion feature. This endpoint bypasses normal sharing restrictions, exposing user information, including email addresses, from all groups within the instance.
Users are advised to update the Nextcloud Calendar app to version 6.2.3 or 5.5.17. If an immediate update is not possible, the Calendar app can be disabled as a temporary workaround.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/nextcloud/calendar/issues/7971 | [email protected] | ExploitIssue TrackingPatch |
| https://github.com/nextcloud/calendar/pull/8197 | [email protected] | Issue TrackingPatch |
| https://github.com/nextcloud/security-advisories/security/advisories/GHSA-r697-74m9-gvf2 | [email protected] | MitigationVendor Advisory |
| https://hackerone.com/reports/3540663 | [email protected] | Permissions Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| nextcloud calendar | >= 5.5.13, < 5.5.17 >= 6.2.0, < 6.2.3 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 3, 2026 | Initial Analysis | [email protected] |
| Jun 1, 2026 | New CVE Received | [email protected] |