CVE-2026-45159

LOW

Nextcloud: Files drop share links for end-to-end encrypted folders allowed to drop files into other folders of the share owner

Title source: cna
STIX 2.1

Description

Nextcloud is an open source content collaboration platform. From versions 1.15.0 to before 1.15.4, 1.16.0 to before 1.16.3, 1.17.0 to before 1.17.1, and 1.18.0 to before 1.18.1, a malicious user with access to an end-to-end encrypted files drop link was able to also drop files into other end-to-end encrypted folders of the share owner. Reading and modifying of other files was not possible. This issue has been patched in versions 1.15.4, 1.16.3, 1.17.1, 1.18.1, and 2.0.0-rc.7.

References (3)

Core 3
Core References
X_Refsource_Misc x_refsource_misc
https://hackerone.com/reports/3304830

Scores

CVSS v3 3.5
EPSS 0.0020
EPSS Percentile 10.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

Details

CWE
CWE-639
Status published
Products (4)
nextcloud/security-advisories >= 1.15.0, < 1.15.4
nextcloud/security-advisories >= 1.16.0, < 1.16.3
nextcloud/security-advisories >= 1.17.0, < 1.17.1
nextcloud/security-advisories >= 1.18.0, < 1.18.1
Published Jun 01, 2026
Tracked Since Jun 01, 2026