Nextcloud · Server · CVE-2026-68493
**Name of the Vulnerable Software and Affected Versions**
The product name cannot be determined (affected versions not specified)
**Description**
A logged-in user can retrieve a list of memberships for a circle they do not belong to by guessing a 62^15 complex unique identifier. This is an Insecure Direct Object Reference (IDOR), which occurs when an application provides direct access to objects based on user-supplied input without sufficient authorization checks.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.