CVE-2026-45545 Details
Description
Nextcloud is an open source content collaboration platform. From versions 0.7.0 to before 0.7.7, 0.8.0 to before 0.8.10, 0.9.0 to before 0.9.8, and 1.0.0 to before 1.0.4, an authenticated attacker with access to the Tables app may be able to execute arbitrary up to 20 bytes long SQL queries, through a stored injection. With carefully crafted input it is possible to break out of the length limitation. The attacker could use this to extract information from the database, or modify data. This issue has been patched in versions 0.7.7, 0.8.10, 0.9.8, 1.0.4, and 2.0.0.
A stored SQL injection vulnerability has been identified in the Nextcloud Tables app, affecting versions 0.7.0 prior to 0.7.7, 0.8.0 prior to 0.8.10, 0.9.0 prior to 0.9.8, and 1.0.0 prior to 1.0.4. This vulnerability allows authenticated attackers with access to the Tables app to execute arbitrary SQL queries, initially limited to 20 bytes. However, with carefully crafted input, it is possible to bypass this length restriction. Exploitation of this vulnerability could lead to unauthorized data extraction or modification within the database.
Users are advised to upgrade the Nextcloud Tables app to version 2.0.0, 1.0.4, 0.9.8, 0.8.10, or 0.7.7. Alternatively, the Tables app can be disabled.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/nextcloud/security-advisories/security/advisories/GHSA-x43f-gmgh-vvjj | [email protected] | MitigationVendor Advisory |
| https://github.com/nextcloud/tables/pull/2309 | [email protected] | Issue TrackingPatch |
| https://hackerone.com/reports/3462991 | [email protected] | Permissions Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| nextcloud tables | >= 0.7.0, < 0.7.7 >= 0.8.0, < 0.8.10 >= 0.9.0, < 0.9.8 >= 1.0.0, < 1.0.4 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 4, 2026 | Initial Analysis | [email protected] |
| Jun 1, 2026 | New CVE Received | [email protected] |