← Back to CVE List
CVE-2026-68493NVD
Vulnerability Summary
After guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships for a circle they are not a member of.
CVSS v3.0 Base Metrics — Score 3.1 (LOW)
Attack VectorNetwork
Attack ComplexityHigh
Privileges RequiredLow
User InteractionNone
ScopeUnchanged
ConfidentialityLow
IntegrityNone
AvailabilityNone
Affected & Patched Versions
- Nextcloud Server >= 32.0.0 and <= 34.0.0
- Nextcloud Server 34.0.0