CVE-2026-45154

Nextcloud is an open source content collaboration platform. From version 2.6.0 to before version 4.3.0, when a previous collective pages was deleted and the collective was shared view-only, guests with access to the collective were able to access the deleted pages directly from the trashbin. This issue has been patched in version 4.3.0.
Configurations

No configuration.

History

01 Jun 2026, 17:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-01 17:17

Updated : 2026-06-01 18:14


NVD link : CVE-2026-45154

Mitre link : CVE-2026-45154

CVE.ORG link : CVE-2026-45154


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control