CVE-2026-45543
Nextcloud is an open source content collaboration platform. From version 4.3.0 to before version 5.2.7, a removed collaborator retains unauthorized read access to uploaded respondent files for the affected form. The scope is limited to uploaded files for forms where that user previously had results access. This issue has been patched in version 5.2.7.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS probability
- 0.27%
- CWE
- CWE-552
- Published
- 2026-06-01
- Last modified
- 2026-06-01
Affected products
- nextcloud security-advisories
Weakness type
Related vulnerabilities
- CVE-2026-68831 — Windows Defender Firewall Service Information Disclosure Vulnerability
- CVE-2026-67402 — An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs...
- CVE-2026-85175 — SiYuan before v3.8.2 TLS Private Key Disclosure via getFile
- CVE-2026-82020 — Hermes Agent 0.16.0 < 0.17.0 Credential Store Overwrite via File-Write Tool
- CVE-2026-53580 — Trilium arbitrary file read and denial of service via file:// URLs in the automatic image-download feature
- CVE-2026-78051 — alexta69 MeTube Cookie File cookies.txt file access
- CVE-2026-54457 — TensorZero: Arbitrary file read and SSRF in TensorZero Gateway's internal object storage endpoint
- CVE-2026-63042 — Apache InLong: Missing authorization on DataNode management endpoints