CVE-2023-28999: Nextcloud Desktop

Medium severity, CVSS 6.4. EPSS: 0.7% chance of exploitation in the next 30 days.

Nextcloud is an open-source productivity platform. In Nextcloud Desktop client 3.0.0 until 3.8.0, Nextcloud Android app 3.13.0 until 3.25.0, and Nextcloud iOS app 3.0.5 until 4.8.0, a malicious server administrator can gain full access to an end-to-end encrypted folder. They can decrypt files, recover the folder structure and add new files.​ This issue is fixed in Nextcloud Desktop 3.8.0, Nextcloud Android 3.25.0, and Nextcloud iOS 4.8.0. No known workarounds are available.

Affected products

  • Nextcloud Desktop: from 3.0.0, before 3.8.0 (fixed in 3.8.0)
  • Nextcloud Nextcloud: from 3.0.5, before 4.8.0 (fixed in 4.8.0); from 3.13.0, before 3.25.0 (fixed in 3.25.0)

Published 2023-04-04. Last modified 2026-06-17.