CVE-2026-45277: Nextcloud Approval

Low severity, CVSS 3.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, authenticated users can check if arbitrary files are associated with specific approval workflows where they can request approval. This issue has been patched in version 2.7.2.

Affected products

  • Nextcloud Approval: before 2.7.2 (fixed in 2.7.2)

Published 2026-06-01. Last modified 2026-07-22.