CVE-2026-45275

MEDIUM

Nextcloud Approval < 2.7.2 - Privilege Escalation via Forced File Sharing

Title source: llm
STIX 2.1

Description

Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, a privilege escalation vulnerability exists in the Approval app that allows a user without sharing permissions to force the system to share a file with approvers. This results in an authorization bypass and privilege escalation, allowing unauthorized distribution of restricted files. This issue has been patched in version 2.7.2.

Scores

CVSS v3 6.5
EPSS 0.0036
EPSS Percentile 27.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-285
Status published
Products (1)
nextcloud/approval < 2.7.2
Published Jun 01, 2026
Tracked Since Jun 02, 2026