CVE-2026-68490: High severity vulnerability
Published Sep 23, 2026
·Updated
Incorrect permission assignment allows local users to obtain sensitive CalDAV/CardDAV information belonging to other accounts.
Event History
Sep 23, 2026
CVE Published
via MITRE·07:52 PM
Data Sourced
via MITRE·07:52 PM
DescriptionWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploiting this issue require remote access?
The issue is described as affecting local users, so an attacker would need local access to the system.