CVE-2026-77165 Details
Description
File owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no recovery path outside of the database.
A vulnerability in Nextcloud version 33.0.3 allows collaborators with write-share permissions to permanently lock file owners out of their files. This is achieved by placing a TYPE_TOKEN lock that survives share revocation and account deletion. The lock has no expiration and the only recovery method is a direct database intervention.
Users can update to the latest Nextcloud maintenance release, where this issue has been resolved.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 21, 2026CISA-ADP
Assessed Sep 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://hackerone.com/reports/3770482 | CISA-ADP | ExploitIssue TrackingTechnical DescriptionVendor |
| https://hackerone.com/reports/3770482 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Nextcloud | 33.0.3 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 21, 2026 | CVE Modified | CISA-ADP |
| Sep 21, 2026 | New CVE Received | [email protected] |
Volerion