Authorization Bypass in Team Folders App by Vendor
CVE-2026-77169

6.5MEDIUM

Key Information:

Vendor

Nextcloud

Vendor
CVE Published:
18 September 2026

What is CVE-2026-77169?

A vulnerability exists within the Team Folders app that allows API/REST-only delegated administrators to sidestep established folder-level authorization controls. This issue arises when used in conjunction with the Workspace app, which is designed to limit administrative privileges for team folder management. By exploiting this flaw, an attacker could gain unauthorized access to restricted folders, compromising the confidentiality and integrity of sensitive information.

Affected Version(s)

Team Folders 13.0.0 < 22.0.0

References

CVSS V3.0

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

qloo (qloo)
.