CVE-2024-22400: Nextcloud SSO & SAML Authentication

Medium severity, CVSS 6.1. EPSS: 0.5% chance of exploitation in the next 30 days.

Nextcloud User Saml is an app for authenticating Nextcloud users using SAML. In affected versions users can be given a link to the Nextcloud server and end up on a uncontrolled thirdparty server. It is recommended that the User Saml app is upgraded to version 5.1.5, 5.2.5, or 6.0.1. There are no known workarounds for this issue.

Affected products

  • Nextcloud SSO & SAML Authentication: from 5.0.0, before 5.1.5 (fixed in 5.1.5); from 5.2.0, before 5.2.5 (fixed in 5.2.5); version 6.0.0 only

Published 2024-01-18. Last modified 2026-06-17.