CVE-2026-68493: Nextcloud Server
Low severity, CVSS 3.1. EPSS: 0.2% chance of exploitation in the next 30 days.
After guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships for a circle they are not a member of.
Affected products
- Nextcloud Server: from 32.0.0, up to and including 34.0.0
Published 2026-09-18. Last modified 2026-09-18.