CVE-2018-3762: Nextcloud Server

Medium severity, CVSS 4.3. EPSS: 0.9% chance of exploitation in the next 30 days.

Nextcloud Server before 12.0.8 and 13.0.3 suffers from improper checks of dropped permissions for incoming shares allowing a user to still request previews for files it should not have access to.

Affected products

  • Nextcloud Nextcloud Server: before 12.0.8 (fixed in 12.0.8); from 13.0.0, before 13.0.3 (fixed in 13.0.3)

Published 2018-07-05. Last modified 2026-06-17.