Description
After guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships for a circle they are not a member of.
Published: 2026-09-18
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Information Disclosure
Action: Assess Impact
AI Analysis

Impact

A logged‑in user can retrieve a list of members of a circle they are not part of by guessing a 62^15 complex unique identifier. The flaw results from inadequate authorization checks on the endpoint that returns circle membership data, allowing the enumeration of private relationships and exposing confidential relational information. This is a CWE‑639 authorization bypass via user‑controlled key.

Affected Systems

The vulnerability affects Nextcloud Server. No specific major or minor version information is available in the public data, so the exact scope of affected deployments is not defined.

Risk and Exploitability

With a CVSS score of 3.1 the issue falls into the low severity range. The EPSS score is reported as < 1%, indicating a very low exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to be authenticated and to successfully guess a 62^15 identifier, which is statistically improbable; consequently the overall risk is moderate to low for most environments.

Generated by OpenCVE AI on September 19, 2026 at 22:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any available patch from Nextcloud that resolves permission checks for circle membership endpoints.
  • Apply rate limiting or brute‑force protection to the circle‑membership API to make guessing attempts impractical.
  • Add explicit authorization checks to ensure that only users who are members of a circle can retrieve its membership list, and log any unauthorized attempts for audit purposes.

Generated by OpenCVE AI on September 19, 2026 at 22:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Sat, 19 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Title Logged‑in User Can Enumerate Memberships of Non‑Members via ID Guessing

Sat, 19 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Title Logged‑in User Can Enumerate Memberships of Non‑Members via ID Guessing

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Nextcloud
Nextcloud server
Vendors & Products Nextcloud
Nextcloud server

Fri, 18 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Description After guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships for a circle they are not a member of.
Weaknesses CWE-639
References
Metrics cvssV3_0

{'score': 3.1, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Nextcloud Server
cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-09-18T19:40:16.781Z

Reserved: 2026-07-30T15:00:00.609Z

Link: CVE-2026-68493

cve-icon Vulnrichment

Updated: 2026-09-18T19:40:12.424Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T02:17:07.350

Modified: 2026-09-18T20:17:21.037

Link: CVE-2026-68493

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T23:00:10Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key