CVE-2026-45156
HIGHNextcloud: Authentication Bypass in ID4me handling via Missing JWT Signature Verification in User OIDC
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-45156. PoCs published by cybertechajju.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-45156, which leverages a missing JWT signature verification in Nextcloud's user_oidc app to bypass authentication and achieve admin takeover. The PoC includes a fake OIDC server and automated ngrok tunneling to deliver forged JWT tokens.
Description
Nextcloud is an open source content collaboration platform. From versions 0.3.0 to before 3.1.0, 5.0.0 to before 5.1.0, and 6.0.0 to before 6.4.0, a missing signature verification in User OIDC allowed a malicious ID4me authority to identify as any user. This issue has been patched in versions 3.1.0, 4.1.0, 5.1.0, 6.4.0 and 8.3.0.
Exploits (1)
This repository contains a functional exploit for CVE-2026-45156, which leverages a missing JWT signature verification in Nextcloud's user_oidc app to bypass authentication and achieve admin takeover. The PoC includes a fake OIDC server and automated ngrok tunneling to deliver forged JWT tokens.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N