Anyone who has view rights on the Calendar.JSONService page, including guest users can exploit this vulnerability by accessing database info, with the exception of passwords.
Remove the Calendar.JSONService page. This will however break some functionalities.
Jira issue: * FULLCAL-82: Calendar.JSONService exposes emails of all users
If you have any questions or comments about this advisory: * Open an issue in Jira XWiki.org * Email us at Security Mailing List
{
"github_reviewed": true,
"github_reviewed_at": "2026-01-09T18:35:57Z",
"severity": "MODERATE",
"nvd_published_at": "2026-01-10T04:16:01Z",
"cwe_ids": [
"CWE-200"
]
}