CVE-2024-46958: Nextcloud Desktop
Critical severity, CVSS 9.1. EPSS: 0.6% chance of exploitation in the next 30 days.
In Nextcloud Desktop Client 3.13.1 through 3.13.3 on Linux, synchronized files (between the server and client) may become world writable or world readable. This is fixed in 3.13.4.
Affected products
- Nextcloud Desktop: from 3.13.1, before 3.13.4 (fixed in 3.13.4)
Published 2024-09-16. Last modified 2026-06-17.