QSearchQSearch

CVE-2026-45284

4.6 MEDIUM

Nextcloud is an open source content collaboration platform

Published: 2026-06-01 · Last updated: 2026-06-03

Severity and scoring

CVSS
4.6 MEDIUM
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L
CWE
CWE-284

Affected products

VendorProduct
nextclouduser_oidc

Description

Nextcloud is an open source content collaboration platform. From version 1.3.6 to before version 8.4.0, an improper check allowed users that where provided by LDAP to still authenticate towards user OIDC after they where deleted. This issue has been patched in version 8.4.0.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2026-45810 Nextcloud is an open source content collaboration platform (6.8 MEDIUM)
  • CVE-2026-45722 Nextcloud is an open source content collaboration platform (7.1 HIGH)
  • CVE-2026-45691 Nextcloud is an open source content collaboration platform (5.9 MEDIUM)
  • CVE-2026-45690 Nextcloud is an open source content collaboration platform (5.9 MEDIUM)
  • CVE-2026-45545 Nextcloud is an open source content collaboration platform (8.2 HIGH)

Same CWE

  • CVE-2026-12212 A vulnerability has been found in hcengineering Huly Platform up to 0.7.0 (4.3 MEDIUM)
  • CVE-2026-12203 A vulnerability was found in HKUDS AI-Trader up to 74caf996f78dcc0c657df8365c8544678a16e215 (5.3 MEDIUM)
  • CVE-2026-53520 Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool (6.5 MEDIUM)
  • CVE-2026-44783 Discourse is an open-source discussion platform (5.4 MEDIUM)
  • CVE-2026-47182 Frappe is a full-stack web application framework