« Volver al listado

CVE-2026-45286

Estado: AnalizadaMedia (4.3)—

Nextcloud is an open source content collaboration platform. From versions 5.5.13 to before 5.5.17, and 6.2.0 to before 6.2.3, an authenticated user can enumerate users on the same Nextcloud instance by using the Calendar app's endpoint for suggesting attendees. The sharing restrictions, applied to other endpoints, were not effective here. This issue has been patched in versions 5.5.17 and 6.2.3.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-45286",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-45286",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-01T19:12:56.174122Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "nextcloud",
          "product": "security-advisories",
          "versions": [
            {
              "status": "affected",
              "version": ">= 5.5.13, < 5.5.17"
            },
            {
              "status": "affected",
              "version": ">= 6.2.0, < 6.2.3"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-06-01T19:16:50.957",
  "references": [
    {
      "url": "https://github.com/nextcloud/calendar/issues/7971",
      "tags": [
        "Exploit",
        "Issue Tracking",
        "Patch"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/nextcloud/calendar/pull/8197",
      "tags": [
        "Issue Tracking",
        "Patch"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/nextcloud/security-advisories/security/advisories/GHSA-r697-74m9-gvf2",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://hackerone.com/reports/3540663",
      "tags": [
        "Permissions Required"
      ],
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Nextcloud is an open source content collaboration platform. From versions 5.5.13 to before 5.5.17, and 6.2.0 to before 6.2.3, an authenticated user can enumerate users on the same Nextcloud instance by using the Calendar app's endpoint for suggesting attendees. The sharing restrictions, applied to other endpoints, were not effective here. This issue has been patched in versions 5.5.17 and 6.2.3."
    },
    {
      "lang": "es",
      "value": "Nextcloud es una plataforma de colaboración de contenido de código abierto. Desde las versiones 5.5.13 hasta antes de la 5.5.17, y de la 6.2.0 hasta antes de la 6.2.3, un usuario autenticado puede enumerar usuarios en la misma instancia de Nextcloud utilizando el endpoint de la aplicación Calendario para sugerir asistentes. Las restricciones de compartición, aplicadas a otros endpoints, no eran efectivas aquí. Este problema ha sido parcheado en las versiones 5.5.17 y 6.2.3."
    }
  ],
  "lastModified": "2026-07-22T08:10:00.117",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:nextcloud:calendar:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1CF598EB-40C6-4DD2-91AB-C6F9E1B3E822",
              "versionEndExcluding": "5.5.17",
              "versionStartIncluding": "5.5.13"
            },
            {
              "criteria": "cpe:2.3:a:nextcloud:calendar:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ED61C839-05B9-4A73-B437-9EA6010FB468",
              "versionEndExcluding": "6.2.3",
              "versionStartIncluding": "6.2.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}