CVE-2018-16466: Nextcloud Server
High severity, CVSS 8.1. EPSS: 1% chance of exploitation in the next 30 days.
Improper revalidation of permissions in Nextcloud Server prior to 14.0.0, 13.0.6 and 12.0.11 lead to not accepting access restrictions by acess tokens.
Affected products
- Nextcloud Nextcloud Server: before 12.0.11 (fixed in 12.0.11); from 13.0.0, before 13.0.6 (fixed in 13.0.6); version 14.0.0 only
Published 2018-10-30. Last modified 2026-06-17.