CVE-2026-68493: Nextcloud Server

Low severity, CVSS 3.1. EPSS: 0.2% chance of exploitation in the next 30 days.

After guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships for a circle they are not a member of.

Affected products

  • Nextcloud Server: from 32.0.0, up to and including 34.0.0

Published 2026-09-18. Last modified 2026-09-18.