Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 03 Jun 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:nextcloud:calendar:*:*:*:*:*:*:*:* |
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nextcloud
Nextcloud calendar |
|
| Vendors & Products |
Nextcloud
Nextcloud calendar |
Mon, 01 Jun 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 01 Jun 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nextcloud is an open source content collaboration platform. From versions 5.5.13 to before 5.5.17, and 6.2.0 to before 6.2.3, an authenticated user can enumerate users on the same Nextcloud instance by using the Calendar app's endpoint for suggesting attendees. The sharing restrictions, applied to other endpoints, were not effective here. This issue has been patched in versions 5.5.17 and 6.2.3. | |
| Title | Nextcloud: Calendar app leaked user identifiers via attendee suggestion endpoint | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-01T19:13:25.363Z
Reserved: 2026-05-11T20:14:43.200Z
Link: CVE-2026-45286
Updated: 2026-06-01T19:13:04.269Z
Status : Analyzed
Published: 2026-06-01T19:16:50.957
Modified: 2026-06-03T20:35:59.817
Link: CVE-2026-45286
No data.
OpenCVE Enrichment
Updated: 2026-06-03T22:00:15Z