PT-2026-45476 · Nextcloud · Nextcloud

·

CVE-2026-45266

·

Published

2026-06-01

·

Updated

2026-06-01

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud versions prior to 21.1.10 Nextcloud versions prior to 22.0.11 Nextcloud versions prior to 23.0.3
Description A low-privileged user can force the microphones of other users to be muted during calls. This occurs due to a missing permission check when using internal signaling in environments where no High-performance Backend is installed.
Recommendations Update to version 21.1.10. Update to version 22.0.11. Update to version 23.0.3.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45266
GHSA-X75R-65HM-CW35

Affected Products

Nextcloud