CVE-2026-45284 Details
Description
Nextcloud is an open source content collaboration platform. From version 1.3.6 to before version 8.4.0, an improper check allowed users that where provided by LDAP to still authenticate towards user OIDC after they where deleted. This issue has been patched in version 8.4.0.
A vulnerability exists in the Nextcloud User OIDC app, specifically in versions 1.3.6 prior to 8.4.0, as well as 5.0.3, 6.1.0, and 6.3.0. The issue arises from an improper check in the LdapService, which allowed deleted LDAP users to still authenticate with the user OIDC app. This vulnerability has been patched in version 8.4.0.
Users of the Nextcloud User OIDC app are advised to upgrade to version 8.4.0. If an immediate upgrade is not possible, the app can be temporarily disabled.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/nextcloud/security-advisories/security/advisories/GHSA-79xf-ffj8-96fm | [email protected] | MitigationVendor Advisory |
| https://github.com/nextcloud/user_oidc/pull/1340 | [email protected] | Issue TrackingPatch |
| https://hackerone.com/reports/3554696 | [email protected] | Permissions Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| nextcloud user oidc | >= 1.3.6, < 8.4.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 3, 2026 | Initial Analysis | [email protected] |
| Jun 1, 2026 | New CVE Received | [email protected] |