CVE-2019-15621: Nextcloud Server
Medium severity, CVSS 6.5. EPSS: 1.1% chance of exploitation in the next 30 days.
Improper permissions preservation in Nextcloud Server 16.0.1 causes sharees to be able to reshare with write permissions when sharing the mount point of a share they received, as a public link.
Affected products
- Nextcloud Nextcloud Server: before 14.0.13 (fixed in 14.0.13); from 15.0.0, before 15.0.9 (fixed in 15.0.9); from 16.0.0, before 16.0.2 (fixed in 16.0.2)
Published 2020-02-04. Last modified 2026-06-17.