Nextcloud CVE-2026-45281 Cross-Account Calendar Takeover
ethiack.com | vulnerability | High | CVE-2026-45281 | #vulnerability-research | #access-control | #calendar-security | #nextcloud | #vulnerability | #ethiack | #cve-2026-45281 | #caldav
Summary
Ethiack shows CVE-2026-45281: an authorization gap in Nextcloud's CalDAV stack lets any authenticated user join another user's calendar-proxy-write group via PROPPATCH, taking over their calendars.
- Vendor
- Nextcloud
- Product
- Nextcloud Server / Calendar
- Affected versions
- Nextcloud Server 32.x < 32.0.9 and 33.x < 33.0.3; affected Enterprise branches 21.x-33.x require their listed security patch
- CVSS
- 8.1
- Published
- Collected
Skip to content