CVE-2026-45277

LOW

Nextcloud Approval < 2.7.2 - Authenticated Exposure of Sensitive Information via Workflow File Association Check

Title source: llm
STIX 2.1

Description

Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, authenticated users can check if arbitrary files are associated with specific approval workflows where they can request approval. This issue has been patched in version 2.7.2.

Scores

CVSS v3 3.3
EPSS 0.0013
EPSS Percentile 2.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-200
Status published
Products (1)
nextcloud/approval < 2.7.2
Published Jun 01, 2026
Tracked Since Jun 02, 2026