CVE-2026-45543

Nextcloud is an open source content collaboration platform. From version 4.3.0 to before version 5.2.7, a removed collaborator retains unauthorized read access to uploaded respondent files for the affected form. The scope is limited to uploaded files for forms where that user previously had results access. This issue has been patched in version 5.2.7.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nextcloud:forms:*:*:*:*:*:*:*:*

History

04 Jun 2026, 16:43

Type Values Removed Values Added
First Time Nextcloud forms
Nextcloud
CPE cpe:2.3:a:nextcloud:forms:*:*:*:*:*:*:*:*
References () https://github.com/nextcloud/forms/pull/3291 - () https://github.com/nextcloud/forms/pull/3291 - Issue Tracking, Patch
References () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-q4fw-6jf8-5vhh - () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-q4fw-6jf8-5vhh - Mitigation, Vendor Advisory
References () https://hackerone.com/reports/3617352 - () https://hackerone.com/reports/3617352 - Permissions Required

01 Jun 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-01 19:16

Updated : 2026-06-04 16:43


NVD link : CVE-2026-45543

Mitre link : CVE-2026-45543

CVE.ORG link : CVE-2026-45543


JSON object : View

Products Affected

nextcloud

  • forms
CWE
CWE-552

Files or Directories Accessible to External Parties