← Back

CVE-2026-45543

nvd nist
Published: Jun 1, 2026Modified: Jul 22, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: security-advisories@github.com (Secondary)

Description

Nextcloud is an open source content collaboration platform. From version 4.3.0 to before version 5.2.7, a removed collaborator retains unauthorized read access to uploaded respondent files for the affected form. The scope is limited to uploaded files for forms where that user previously had results access. This issue has been patched in version 5.2.7.

Affected (1)

Products: Nextcloud: Forms
1 product
Forms
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 4.3.0 to 5.2.7

References (3)

Source: security-advisories@github.com
Issue TrackingPatch
Source: security-advisories@github.com
MitigationVendor Advisory
Source: security-advisories@github.com
Permissions Required

Timeline

No history available yet.