Junglewise Threat Intelligence

CVE-2026-45281: Nextcloud Server authorization bypass in calendar delegation

CVE-2026-45281 · Severity: high · CVSS 8.1 · Published 2026-06-01

Technologies: Nextcloud Server, Nextcloud Enterprise Server. Vendors: Nextcloud.

Executive brief

Nextcloud is a content collaboration platform used for file sharing and scheduling. A security flaw allows an authenticated user to gain full access to another user's calendar if they know the target's specific URL. This could lead to the unauthorized viewing, modification, or deletion of sensitive meeting information and personal schedules.

Technical details

An authorization bypass (CWE-639) exists in the Nextcloud calendar backend due to improper Access Control List (ACL) enforcement during calendar delegation. An authenticated attacker who knows another user's principal URL can send crafted requests to the calendar-proxy endpoints to gain full read/write access to that user's calendar. The vulnerability affects the 'group-member-set' update mechanism within the CalDAV implementation. Exploitation requires network access and valid user credentials but no user interaction. Patches have been released for both Community and Enterprise editions to introduce proper ACLs for calendar delegation.

Affected products

  • Nextcloud Nextcloud Server 32.0.0 to < 32.0.9, 33.0.0 to < 33.0.3
  • Nextcloud Nextcloud Enterprise Server 21.0.0 to < 21.0.9.23, 22.0.0 to < 22.2.10.39, 23.0.0 to < 23.0.12.35, 24.0.0 to < 24.0.12.34, 25.0.0 to < 25.0.13.29, 26.0.0 to < 26.0.13.26, 27.0.0 to < 27.1.11.26, 28.0.0 to < 28.0.14.17, 29.0.0 to < 29.0.16.16, 30.0.0 to < 30.0.17.9, 31.0.0 to < 31.0.14.5, 32.0.0 to < 32.0.9, 33.0.0 to < 33.0.3

Timeline

  • 2026-04-28: other: Fix pull request submitted to Nextcloud server repository
  • 2026-05-12: advisory: GitHub Security Advisory published
  • 2026-06-01: disclosed: CVE published to NVD

References

Related threats