PT-2026-45475 · Nextcloud · Nextcloud
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Nextcloud versions 17.0.0 through 17.0.14
Nextcloud versions 18.0.0 through 18.1.11
Nextcloud versions 19.0.0 through 19.1.15
Nextcloud versions 20.0.0 through 20.1.10
Nextcloud versions 21.0.0 through 21.0.3
Description
An Access Control List (ACL) permission bypass exists in team folders. A user granted READ and CREATE permissions, but lacking UPDATE permissions, can unauthorizedly rename files within the team folder.
Recommendations
Update to version 17.0.15
Update to version 18.1.12
Update to version 19.1.16
Update to version 20.1.11
Update to version 21.0.4
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nextcloud