Token Lock Vulnerability in File Management System by Vendor X
CVE-2026-77165

6.5MEDIUM

Key Information:

Vendor

Nextcloud

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-77165?

A serious issue has been identified in Vendor X's File Management System where users are unable to unlock TYPE_TOKEN locks that have been applied by others. This limitation prevents the original file owners from regaining access and effectively leaves critical files locked indefinitely. The only way to resolve this issue is through direct database intervention, which poses significant security risks and operational challenges.

Affected Version(s)

Server 32.0.0 <= 34.0.0

References

CVSS V3.0

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

rz1027 (rz1027)
.