Authorization Flaw in Nextcloud Collaboration Platform
CVE-2026-45543

5.3MEDIUM

Key Information:

Vendor

Nextcloud

Vendor
CVE Published:
1 June 2026

What is CVE-2026-45543?

Nextcloud, an open-source collaboration platform, has an authorization flaw that permits previously removed collaborators to retain unauthorized read access to uploaded files associated with forms. This vulnerability affects versions 4.3.0 up to, but not including, 5.2.7. The issue has been addressed in version 5.2.7, wherein access controls have been properly enforced to prevent unauthorized data access, thereby safeguarding sensitive information uploaded by users.

Affected Version(s)

security-advisories >= 4.3.0, < 5.2.7

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.