Missing Permissions Check in Nextcloud Content Collaboration Platform
CVE-2026-45267
6.5MEDIUM
What is CVE-2026-45267?
Nextcloud, an open-source content collaboration platform, was found to have a vulnerability that enabled unauthorized users to access the form submissions of other users due to a lack of permission checks. This issue has been addressed in version 5.2.6, ensuring that only authorized users can view form submissions, thereby securing user data from unauthorized access.
Affected Version(s)
security-advisories < 5.2.6