Impact
A logged‑in user can retrieve a list of members of a circle they are not part of by guessing a 62^15 complex unique identifier. The flaw results from inadequate authorization checks on the endpoint that returns circle membership data, allowing the enumeration of private relationships and exposing confidential relational information. This is a CWE‑639 authorization bypass via user‑controlled key.
Affected Systems
The vulnerability affects Nextcloud Server. No specific major or minor version information is available in the public data, so the exact scope of affected deployments is not defined.
Risk and Exploitability
With a CVSS score of 3.1 the issue falls into the low severity range. The EPSS score is reported as < 1%, indicating a very low exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to be authenticated and to successfully guess a 62^15 identifier, which is statistically improbable; consequently the overall risk is moderate to low for most environments.
OpenCVE Enrichment