Executive brief
Nextcloud is a collaboration platform used for file sharing and team coordination. A flaw in its Calendar application allowed logged-in users to see the names and email addresses of other users on the same system, even when privacy settings were configured to prevent this. This could lead to unauthorized internal data discovery or the exposure of user identities across different departments or client groups.
Technical details
An information disclosure vulnerability (CWE-200) exists in the Nextcloud Calendar app's attendee suggestion endpoint. While Nextcloud provides administrative settings to restrict user autocompletion and sharing visibility between groups, this specific endpoint failed to respect those global sharing restrictions. An authenticated attacker can send requests to the suggestion endpoint to systematically enumerate user identifiers and email addresses across the entire instance. The issue is resolved in Calendar app versions 5.5.17 and 6.2.3.
Affected products
- Nextcloud Calendar app 5.5.13 to < 5.5.17, 6.2.0 to < 6.2.3
Timeline
- 2026-02-09: disclosed: Initial bug report on GitHub
- 2026-04-23: patched: Fix merged into main branch
- 2026-05-12: advisory: Vendor security advisory published
- 2026-06-01: other: CVE published to NVD