CVE-2023-35171: Nextcloud Server
Medium severity, CVSS 6.1. EPSS: 0.6% chance of exploitation in the next 30 days.
NextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform. Starting in version 26.0.0 and prior to version 26.0.2, an attacker could supply a URL that redirects an unsuspecting victim from a legitimate domain to an attacker's site. Nextcloud Server and Nextcloud Enterprise Server 26.0.2 contain a patch for this issue. No known workarounds are available.
Affected products
- Nextcloud Nextcloud Server: from 26.0.0, before 26.0.2 (fixed in 26.0.2)
Published 2023-06-23. Last modified 2026-06-17.