CVE-2026-45282 Details
Description
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, an authenticated attacker can access attachments of link shares when knowing the share token, circumventing password protection or download restrictions. It is applicable to any file that is shared directly, as the attacker only needs to know a documentId they own, apart of the mentioned share token. For shared folders the attacker has to know or guess a documentId of a file that is included inside the folder, making it much harder to exploit. The attacker can only extract an attachments, but not the file shared file or folder itself. It is recommended that the Nextcloud Server is upgraded to 33.0.3 or 32.0.9. It is recommended that the Nextcloud Enterprise Server is upgraded to 33.0.3, 32.0.9, 31.0.14.5, 30.0.17.9, 29.0.16.16, 28.0.14.17 or 27.1.11.5
A vulnerability exists in Nextcloud Server versions 32.0.0 prior to 32.0.9 and 33.0.0 prior to 33.0.3, as well as in Nextcloud Enterprise Server versions 27.0.0, 28.0.0, 29.0.0, 30.0.0, 31.0.0, 32.0.0, and 33.0.0. This vulnerability allows an authenticated attacker to access attachments from link shares by knowing the share token, thereby bypassing password protection and download restrictions. The issue affects any directly shared file, as the attacker only needs to know a document ID they own, along with the share token. For shared folders, the attacker must know or guess a document ID of a file within the folder, making exploitation more difficult. The vulnerability allows extraction of attachments but not the shared file or folder itself.
Users are advised to upgrade Nextcloud Server to version 33.0.3 or 32.0.9. Nextcloud Enterprise Server users should upgrade to version 33.0.3, 32.0.9, 31.0.14.5, 30.0.17.9, 29.0.16.16, 28.0.14.17, or 27.1.11.5.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/nextcloud/security-advisories/security/advisories/GHSA-35fx-69q6-xpjr | [email protected] | MitigationVendor Advisory |
| https://github.com/nextcloud/text/pull/8499 | [email protected] | Issue TrackingPatch |
| https://hackerone.com/reports/3577244 | [email protected] | Permissions Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| nextcloud nextcloud server | >= 32.0.0, < 32.0.9 >= 33.0.0, < 33.0.3 >= 27.0.0, < 27.1.11.5 >= 28.0.0, < 28.0.14.17 >= 29.0.0, < 29.0.16.16 >= 30.0.0, < 30.0.17.9 >= 31.0.0, < 31.0.14.5 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 3, 2026 | Initial Analysis | [email protected] |
| Jun 1, 2026 | New CVE Received | [email protected] |