PT-2026-45528 · Nextcloud · Security-Advisories
Dorra Jaouad
·
Published
2026-06-01
·
Updated
2026-06-01
·
CVE-2026-45284
CVSS v3.1
4.6
Medium
| Vector | AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L |
Nextcloud is an open source content collaboration platform. From version 1.3.6 to before version 8.4.0, an improper check allowed users that where provided by LDAP to still authenticate towards user OIDC after they where deleted. This issue has been patched in version 8.4.0.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Security-Advisories