CVE-2026-45264

MEDIUM

Nextcloud: ACL Rename Permission Bypass in Team Folders Allows Unauthorized File Renames

Title source: cna
STIX 2.1

Description

Nextcloud is an open source content collaboration platform. From versions 17.0.0 to before 17.0.15, 18.0.0 to before 18.1.12, 19.0.0 to before 19.1.16, 20.0.0 to before 20.1.11, and 21.0.0 to before 21.0.4, a user with READ and CREATE permission, but no UPDATE permission for a team folder can rename files in the team folder. This issue has been patched in versions 17.0.15, 18.1.12, 19.1.16, 20.1.11, and 21.0.4.

References (3)

Core 3
Core References
X_Refsource_Misc x_refsource_misc
https://github.com/nextcloud/groupfolders/pull/4361
X_Refsource_Misc x_refsource_misc
https://hackerone.com/reports/3540673

Scores

CVSS v3 4.3
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-284
Status published
Products (5)
nextcloud/security-advisories >= 17.0.0, < 17.0.15
nextcloud/security-advisories >= 18.0.0, < 18.1.12
nextcloud/security-advisories >= 19.0.0, < 19.1.16
nextcloud/security-advisories >= 20.0.0, < 20.1.11
nextcloud/security-advisories >= 21.0.0, < 21.0.4
Published Jun 01, 2026
Tracked Since Jun 01, 2026