CVE-2019-15624: Nextcloud Server

Medium severity, CVSS 4.9. EPSS: 1.5% chance of exploitation in the next 30 days.

Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders.

Affected products

  • Nextcloud Nextcloud Server: before 14.0.11 (fixed in 14.0.11); from 15.0.0, before 15.0.8 (fixed in 15.0.8)
  • Opensuse Backports: version sle-15 only
  • Suse Suse Linux Enterprise Server: version 12 only

Published 2020-02-04. Last modified 2026-06-17.