CVE-2026-45284

MEDIUM

Nextcloud user_oidc 1.3.6-8.3.9 - Improper Access Control for Deleted LDAP Users

Title source: llm
STIX 2.1

Description

Nextcloud is an open source content collaboration platform. From version 1.3.6 to before version 8.4.0, an improper check allowed users that where provided by LDAP to still authenticate towards user OIDC after they where deleted. This issue has been patched in version 8.4.0.

References (3)

Core 3
Core References
Issue Tracking x_refsource_misc
https://github.com/nextcloud/user_oidc/pull/1340
Third Party Advisory x_refsource_misc
https://hackerone.com/reports/3554696

Scores

CVSS v3 4.6
EPSS 0.0019
EPSS Percentile 9.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (2)
nextcloud/security-advisories >= 1.3.6, < 8.4.0
nextcloud/user_oidc 1.3.6 - 8.4.0
Published Jun 01, 2026
Tracked Since Jun 02, 2026