CVE-2023-39960

MEDIUM

Nextcloud Server 22.0.0-22.2.10.14, 25.0.0-25.0.9 - Unauthenticated Password Brute Force via WebDAV API

Title source: llm
STIX 2.1

Description

Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. In Nextcloud Server starting with 25.0.0 and prior to 25.09 and 26.04; as well as Nextcloud Enterprise Server starting with 22.0.0 and prior to 22.2.10.14, 23.0.12.9, 24.0.12.5, 25.0.9, and 26.0.4; missing protection allows an attacker to brute force passwords on the WebDAV API. Nextcloud Server 25.0.9 and 26.0.4 and Nextcloud Enterprise Server 22.2.10.14, 23.0.12.9, 24.0.12.5, 25.0.9, and 26.0.4 contain patches for this issue. No known workarounds are available.

References (3)

Core 3
Core References
Issue Tracking, Patch x_refsource_misc
https://github.com/nextcloud/server/pull/38046
Third Party Advisory x_refsource_misc
https://hackerone.com/reports/1924212

Scores

CVSS v3 5.0
EPSS 0.0024
EPSS Percentile 47.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-307
Status published
Products (2)
nextcloud/nextcloud_server 22.0.0 - 22.2.10.14
nextcloud/nextcloud_server 25.0.0 - 25.0.9
Published Oct 13, 2023
Tracked Since Feb 18, 2026