CVE-2018-3775: Nextcloud Server
High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.
Improper Authentication in Nextcloud Server prior to version 12.0.3 would allow an attacker that obtained user credentials to bypass the 2 Factor Authentication.
Affected products
- Nextcloud Nextcloud Server: before 12.0.3 (fixed in 12.0.3)
Published 2018-08-12. Last modified 2026-06-17.