Membership Information Disclosure in Affected Product by Vendor
CVE-2026-68493

3.1LOW

Key Information:

Vendor

Nextcloud

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-68493?

A vulnerability exists in the affected product where a malicious actor, after successfully guessing a complex unique identifier, can exploit this flaw to reveal a list of memberships from circles they do not belong to. This unauthorized access could lead to privacy violations and unauthorized insights into user relationships and group memberships.

Affected Version(s)

Server 32.0.0 <= 34.0.0

References

CVSS V3.0

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Melanie (milou)
.