CVE-2026-45810: Nextcloud Server
Medium severity, CVSS 6.8. EPSS: 0.4% chance of exploitation in the next 30 days.
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.12, and 32.0.0 to before 32.0.3, a missing check of a relation allowed authenticated users with access to any file comment, to read the content of all comments. It is recommended that the Nextcloud Server is upgraded to 31.0.12 or 32.0.3. It is recommended that the Nextcloud Enterprise Server is upgraded to 21.0.9.20, 22.2.10.35, 23.0.12.31, 24.0.12.30, 25.0.13.25, 26.0.13.22, 27.1.11.22, 28.0.14.13, 29.0.16.10, 30.0.17.5, 31.0.12 or 32.0.3
Affected products
- Nextcloud Nextcloud Server: from 31.0.0, before 31.0.12 (fixed in 31.0.12); from 32.0.0, before 32.0.3 (fixed in 32.0.3); from 21.0.0, before 21.0.9.20 (fixed in 21.0.9.20); from 22.0.0, before 22.2.10.35 (fixed in 22.2.10.35); from 23.0.0, before 23.0.12.31 (fixed in 23.0.12.31); from 24.0.0, before 24.0.12.30 (fixed in 24.0.12.30); …
Published 2026-06-01. Last modified 2026-07-22.