1.
ethiack.com | vulnerability | High | | original ↗ | #vulnerability-research | #access-control | #calendar-security | #nextcloud
Ethiack shows CVE-2026-45281: an authorization gap in Nextcloud's CalDAV stack lets any authenticated user join another user's calendar-proxy-write group via PROPPATCH, taking over their calendars.
Skip to content