CVE-2026-45286

Source
https://cve.org/CVERecord?id=CVE-2026-45286
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45286.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-45286
Aliases
  • GHSA-r697-74m9-gvf2
Published
2026-06-01T16:59:36.865Z
Modified
2026-07-24T03:56:54.671683522Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Nextcloud: Calendar app leaked user identifiers via attendee suggestion endpoint
Details

Nextcloud is an open source content collaboration platform. From versions 5.5.13 to before 5.5.17, and 6.2.0 to before 6.2.3, an authenticated user can enumerate users on the same Nextcloud instance by using the Calendar app's endpoint for suggesting attendees. The sharing restrictions, applied to other endpoints, were not effective here. This issue has been patched in versions 5.5.17 and 6.2.3.

Database specific
{
    "cwe_ids": [
        "CWE-200"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45286.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/nextcloud/calendar

Affected ranges

Type
GIT
Repo
https://github.com/nextcloud/calendar
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "5.5.13"
        },
        {
            "fixed": "5.5.17"
        },
        {
            "introduced": "6.2.0"
        },
        {
            "fixed": "6.2.3"
        }
    ],
    "source": "CPE_RANGE",
    "cpe": "cpe:2.3:a:nextcloud:calendar:*:*:*:*:*:*:*:*"
}

Affected versions

v5.*
v5.5.13
v5.5.14
v5.5.15
v5.5.16
v6.*
v6.2.0
v6.2.1
v6.2.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45286.json"