CVE-2018-3775: Nextcloud Server

High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.

Improper Authentication in Nextcloud Server prior to version 12.0.3 would allow an attacker that obtained user credentials to bypass the 2 Factor Authentication.

Affected products

  • Nextcloud Nextcloud Server: before 12.0.3 (fixed in 12.0.3)

Published 2018-08-12. Last modified 2026-06-17.