CVE-2026-45266: Nextcloud Security-Advisories

Low severity, CVSS 3.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Nextcloud is an open source content collaboration platform. Prior to versions 21.1.10, 22.0.11, and 23.0.3, a low-privileged user can force other user's microphones to be muted in calls when no High-performance Backend is installed. This issue has been patched in versions 21.1.10, 22.0.11, and 23.0.3.

Affected products

  • Nextcloud Security-Advisories: before 21.1.10 (fixed in 21.1.10); before 22.0.11 (fixed in 22.0.11); before 23.0.3 (fixed in 23.0.3)

Published 2026-06-01. Last modified 2026-07-22.