PT-2026-45472 · Nextcloud · User Oidc

·

CVE-2026-45156

·

Published

2026-01-07

·

Updated

2026-06-29

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud versions 0.3.0 through 3.0.x Nextcloud versions 5.0.0 through 5.0.x Nextcloud versions 6.0.0 through 6.3.x
Description A missing signature verification in User OIDC allows a malicious ID4me authority to identify as any user. This occurs due to the lack of JWT (JSON Web Token) signature verification, which is a standard used to securely transmit information between parties as a JSON object.
Recommendations Update versions 0.3.0 through 3.0.x to version 3.1.0. Update versions 5.0.0 through 5.0.x to version 5.1.0. Update versions 6.0.0 through 6.3.x to version 6.4.0.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08694
CVE-2026-45156
GHSA-QQGV-FQWP-MJPP

Affected Products

User Oidc