CVE-2026-45156

HIGH

Nextcloud: Authentication Bypass in ID4me handling via Missing JWT Signature Verification in User OIDC

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-45156. PoCs published by cybertechajju.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-45156, which leverages a missing JWT signature verification in Nextcloud's user_oidc app to bypass authentication and achieve admin takeover. The PoC includes a fake OIDC server and automated ngrok tunneling to deliver forged JWT tokens.

Description

Nextcloud is an open source content collaboration platform. From versions 0.3.0 to before 3.1.0, 5.0.0 to before 5.1.0, and 6.0.0 to before 6.4.0, a missing signature verification in User OIDC allowed a malicious ID4me authority to identify as any user. This issue has been patched in versions 3.1.0, 4.1.0, 5.1.0, 6.4.0 and 8.3.0.

Exploits (1)

github WORKING POC
by cybertechajju · pythonpoc
https://github.com/cybertechajju/CVE-2026-45156-POC

This repository contains a functional exploit for CVE-2026-45156, which leverages a missing JWT signature verification in Nextcloud's user_oidc app to bypass authentication and achieve admin takeover. The PoC includes a fake OIDC server and automated ngrok tunneling to deliver forged JWT tokens.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Nextcloud user_oidc app
No auth needed
Prerequisites: Nextcloud instance with user_oidc app installed · ngrok authtoken for tunneling
mistral-large-3 · analyzed Jun 24, 2026 Full analysis →

References (3)

Core 3
Core References
X_Refsource_Misc x_refsource_misc
https://github.com/nextcloud/user_oidc/pull/1285
X_Refsource_Misc x_refsource_misc
https://hackerone.com/reports/3489490

Scores

CVSS v3 8.1
EPSS 0.0041
EPSS Percentile 33.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-287
Status published
Products (3)
nextcloud/security-advisories >= 0.3.0, < 3.1.0
nextcloud/security-advisories >= 5.0.0, < 5.1.0
nextcloud/security-advisories >= 6.0.0, < 6.4.0
Published Jun 01, 2026
Tracked Since Jun 01, 2026