← Back

CVE-2026-45284

nvd nist
Published: Jun 1, 2026Modified: Jul 22, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Nextcloud is an open source content collaboration platform. From version 1.3.6 to before version 8.4.0, an improper check allowed users that where provided by LDAP to still authenticate towards user OIDC after they where deleted. This issue has been patched in version 8.4.0.

Affected (1)

Products: Nextcloud: User Oidc
1 product
User Oidc
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 1.3.6 to 8.4.0

References (3)

Source: security-advisories@github.com
MitigationVendor Advisory
Source: security-advisories@github.com
Issue TrackingPatch
Source: security-advisories@github.com
Permissions Required

Timeline

No history available yet.