CVE-2026-77169: Nextcloud Team Folders

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed API/REST-only delegated administrators to bypass folder-level authorization controls. The workspace app enables organizations to delegate limited administrative privileges for team folder management via API/REST only, restricting access to folders for which the admin has advanced permissions.

Affected products

  • Nextcloud Team Folders: from 13.0.0, before 22.0.0 (fixed in 22.0.0)

Published 2026-09-18. Last modified 2026-09-18.