CVE-2026-45264
MEDIUMNextcloud: ACL Rename Permission Bypass in Team Folders Allows Unauthorized File Renames
Title source: cnaDescription
Nextcloud is an open source content collaboration platform. From versions 17.0.0 to before 17.0.15, 18.0.0 to before 18.1.12, 19.0.0 to before 19.1.16, 20.0.0 to before 20.1.11, and 21.0.0 to before 21.0.4, a user with READ and CREATE permission, but no UPDATE permission for a team folder can rename files in the team folder. This issue has been patched in versions 17.0.15, 18.1.12, 19.1.16, 20.1.11, and 21.0.4.
References (3)
Core 3
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-wx2x-822r-rvmf
X_Refsource_Misc x_refsource_misc
https://github.com/nextcloud/groupfolders/pull/4361
X_Refsource_Misc x_refsource_misc
https://hackerone.com/reports/3540673
Scores
CVSS v3
4.3
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Details
CWE
CWE-284
Status
published
Products (5)
nextcloud/security-advisories
>= 17.0.0, < 17.0.15
nextcloud/security-advisories
>= 18.0.0, < 18.1.12
nextcloud/security-advisories
>= 19.0.0, < 19.1.16
nextcloud/security-advisories
>= 20.0.0, < 20.1.11
nextcloud/security-advisories
>= 21.0.0, < 21.0.4
Published
Jun 01, 2026
Tracked Since
Jun 01, 2026