CVE-2019-15610: Nextcloud Circles

Medium severity, CVSS 4.3. EPSS: 0.8% chance of exploitation in the next 30 days.

Improper authorization in the Circles app 0.17.7 causes retaining access when an email address was removed from a circle.

Affected products

  • Nextcloud Circles: before 0.16.11 (fixed in 0.16.11); from 0.16.12, before 0.17.8 (fixed in 0.17.8)

Published 2020-02-04. Last modified 2026-06-17.