CVE-2020-8154: Nextcloud Server

High severity, CVSS 7.7. EPSS: 1.8% chance of exploitation in the next 30 days.

An Insecure direct object reference vulnerability in Nextcloud Server 18.0.2 allowed an attacker to remote wipe devices of other users when sending a malicious request directly to the endpoint.

Affected products

  • Nextcloud Nextcloud Server: before 17.0.5 (fixed in 17.0.5); from 18.0.0, before 18.0.3 (fixed in 18.0.3)

Published 2020-05-12. Last modified 2026-06-17.