CVE-2026-77165
- EPSS 0.25%
- Veröffentlicht 21.09.2026 15:25:33
- Zuletzt bearbeitet 22.09.2026 20:00:03
File owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no recovery path outside of the database.
CVE-2026-82985
- EPSS 0.2%
- Veröffentlicht 18.09.2026 01:26:04
- Zuletzt bearbeitet 18.09.2026 20:17:25
The Photos app's filter-based "smart albums" build their file listing using the search configuration (photosSourceFolders) of the user viewing the album, rather than the album owner's configuration. When an album owner shares a smart album with anoth...
CVE-2026-77164
- EPSS 0.13%
- Veröffentlicht 18.09.2026 01:26:04
- Zuletzt bearbeitet 18.09.2026 20:17:22
Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instance is established, and explicitly allows local/private addresses for this request, bypassing Nextcloud's core SSRF protections. T...
CVE-2026-68493
- EPSS 0.14%
- Veröffentlicht 18.09.2026 01:26:04
- Zuletzt bearbeitet 18.09.2026 20:17:21
After guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships for a circle they are not a member of.
CVE-2026-45157
- EPSS 0.23%
- Veröffentlicht 01.06.2026 17:17:09
- Zuletzt bearbeitet 22.07.2026 07:10:00
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, when a malicious user has access to a file share of a user, they could use this share token to also ac...
CVE-2026-45155
- EPSS 0.2%
- Veröffentlicht 01.06.2026 17:17:09
- Zuletzt bearbeitet 22.07.2026 07:10:00
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.7 and 33.0.0 to before 33.0.1, a missing access check on API level allowed to add unknown circles by their ID directly to other circle...
CVE-2026-45810
- EPSS 0.25%
- Veröffentlicht 01.06.2026 17:13:21
- Zuletzt bearbeitet 22.07.2026 08:10:00
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.12, and 32.0.0 to before 32.0.3, a missing check of a relation allowed authenticated users with access to any file comment, to read th...
CVE-2026-45691
- EPSS 0.29%
- Veröffentlicht 01.06.2026 17:09:48
- Zuletzt bearbeitet 22.07.2026 08:10:00
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, a pre-2FA session cookie (created after successful password authentication but before TOTP completion)...
CVE-2026-45690
- EPSS 0.29%
- Veröffentlicht 01.06.2026 17:08:04
- Zuletzt bearbeitet 22.07.2026 08:10:00
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, an authentication bypass vulnerability allowed attackers with knowledge of a user's password to circum...
CVE-2026-45283
- EPSS 0.21%
- Veröffentlicht 01.06.2026 16:53:50
- Zuletzt bearbeitet 22.07.2026 07:10:00
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.2, and 33.0.0 to before 33.0.1, the files_lock app did not properly validate the ownership of files when processing DAV lock and unloc...