Session Handling Vulnerability in Nextcloud Server by Nextcloud
CVE-2025-47790
What is CVE-2025-47790?
Nextcloud Server and Nextcloud Enterprise Server are affected by a session handling flaw that allows for bypassing the second factor of authentication under specific configuration conditions. When the remember_login_cookie_lifetime is set to 0, users may inadvertently skip the second factor confirmation after a successful username and password login if the session expires, and the selection page is reloaded. To mitigate this vulnerability, it is recommended to update to the latest patched versions and adjust the remember_login_cookie_lifetime setting in config.php to prevent old sessions from being exploited.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
security-advisories >= 26.0.0, < 26.0.13.15 < 26.0.0, 26.0.13.15
security-advisories >= 27.0.0, < 27.1.11.15 < 27.0.0, 27.1.11.15
security-advisories >= 28.0.0, < 28.0.14.6 < 28.0.0, 28.0.14.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved