CVE-2026-45285 Details
Description
Nextcloud is an open source content collaboration platform. From versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, when a user shares a folder or file with a Nextcloud Team that includes an external member (a person added via email address who does not have a Nextcloud account), the system automatically creates a public link for that external member. This public link is not displayed in the share section of the folder, so the folder owner has no knowledge of its existence. It is sent via email to the external member. It grants the same permissions (read, write, delete, reshare, download) as the Team’s access. An attacker who receives or intercepts this link can access, modify, delete, reshare, and download all data in the shared folder without any further authentication. The folder owner cannot see or revoke the link through the normal sharing interface. This issue has been patched in versions 32.0.9 and 33.0.3.
A vulnerability exists in Nextcloud versions 32.0.0 prior to 32.0.9 and 33.0.0 prior to 33.0.3, allowing the automatic creation of public links for external members when files or folders are shared with a Nextcloud Team. External members, added via email and without a Nextcloud account, receive these links through email, granting them the same permissions as the Team's access. The links are not visible to the folder owner, who cannot revoke them through the normal sharing interface. This oversight enables unauthorized access and manipulation of shared data by anyone who intercepts or receives the link.
Users are advised to upgrade Nextcloud Server to versions 32.0.9 or 33.0.3. Nextcloud Enterprise Server users should also upgrade to versions 32.0.9 or 33.0.3.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/nextcloud/circles/pull/2454 | [email protected] | Issue TrackingPatch |
| https://github.com/nextcloud/security-advisories/security/advisories/GHSA-r3xh-x86g-hw4m | [email protected] | Vendor Advisory |
| https://hackerone.com/reports/3625932 | [email protected] | Permissions Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| nextcloud nextcloud server | >= 32.0.0, < 32.0.9 >= 33.0.0, < 33.0.3 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 3, 2026 | Initial Analysis | [email protected] |
| Jun 1, 2026 | New CVE Received | [email protected] |