PT-2026-45476 · Nextcloud · Nextcloud
CVSS v3.1
3.5
Low
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Nextcloud versions prior to 21.1.10
Nextcloud versions prior to 22.0.11
Nextcloud versions prior to 23.0.3
Description
A low-privileged user can force the microphones of other users to be muted during calls. This occurs due to a missing permission check when using internal signaling in environments where no High-performance Backend is installed.
Recommendations
Update to version 21.1.10.
Update to version 22.0.11.
Update to version 23.0.3.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nextcloud