CVE-2024-37887: Nextcloud Server

Low severity, CVSS 3.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Nextcloud Server is a self hosted personal cloud system. Private shared calendar events' recurrence exceptions can be read by sharees. It is recommended that the Nextcloud Server is upgraded to 27.1.10 or 28.0.6 or 29.0.1 and that the Nextcloud Enterprise Server is upgraded to 27.1.10 or 28.0.6 or 29.0.1.

Affected products

  • Nextcloud Nextcloud Server: from 27.0.0, before 27.1.10 (fixed in 27.1.10); from 28.0.0, up to and including 28.0.6; from 28.0.0, before 28.0.6 (fixed in 28.0.6); version 29.0.0 only

Published 2024-06-14. Last modified 2026-06-17.