PT-2026-45475 · Nextcloud · Nextcloud

·

CVE-2026-45264

·

Published

2026-06-01

·

Updated

2026-06-01

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud versions 17.0.0 through 17.0.14 Nextcloud versions 18.0.0 through 18.1.11 Nextcloud versions 19.0.0 through 19.1.15 Nextcloud versions 20.0.0 through 20.1.10 Nextcloud versions 21.0.0 through 21.0.3
Description An Access Control List (ACL) permission bypass exists in team folders. A user granted READ and CREATE permissions, but lacking UPDATE permissions, can unauthorizedly rename files within the team folder.
Recommendations Update to version 17.0.15 Update to version 18.1.12 Update to version 19.1.16 Update to version 20.1.11 Update to version 21.0.4

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45264
GHSA-WX2X-822R-RVMF

Affected Products

Nextcloud