Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Nextcloud CVE-2026-45281 Cross-Account Calendar Takeover

Summary

Ethiack shows CVE-2026-45281: an authorization gap in Nextcloud's CalDAV stack lets any authenticated user join another user's calendar-proxy-write group via PROPPATCH, taking over their calendars.
Vendor
Nextcloud
Product
Nextcloud Server / Calendar
Affected versions
Nextcloud Server 32.x < 32.0.9 and 33.x < 33.0.3; affected Enterprise branches 21.x-33.x require their listed security patch
CVSS
8.1
Published
Collected

original ↗

Related coverage

back