CVE-2026-45264: Nextcloud Security-Advisories
Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.
Nextcloud is an open source content collaboration platform. From versions 17.0.0 to before 17.0.15, 18.0.0 to before 18.1.12, 19.0.0 to before 19.1.16, 20.0.0 to before 20.1.11, and 21.0.0 to before 21.0.4, a user with READ and CREATE permission, but no UPDATE permission for a team folder can rename files in the team folder. This issue has been patched in versions 17.0.15, 18.1.12, 19.1.16, 20.1.11, and 21.0.4.
Affected products
- Nextcloud Security-Advisories: from 17.0.0, before 17.0.15 (fixed in 17.0.15); from 18.0.0, before 18.1.12 (fixed in 18.1.12); from 19.0.0, before 19.1.16 (fixed in 19.1.16); from 20.0.0, before 20.1.11 (fixed in 20.1.11); from 21.0.0, before 21.0.4 (fixed in 21.0.4)
Published 2026-06-01. Last modified 2026-07-22.