CVE-2019-15610: Nextcloud Circles
Medium severity, CVSS 4.3. EPSS: 0.8% chance of exploitation in the next 30 days.
Improper authorization in the Circles app 0.17.7 causes retaining access when an email address was removed from a circle.
Affected products
- Nextcloud Circles: before 0.16.11 (fixed in 0.16.11); from 0.16.12, before 0.17.8 (fixed in 0.17.8)
Published 2020-02-04. Last modified 2026-06-17.