Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.12, and 32.0.0 to before 32.0.3, a missing check of a relation allowed authenticated users with access to any file comment, to read the content of all comments. It is recommended that the Nextcloud Server is upgraded to 31.0.12 or 32.0.3. It is recommended that the Nextcloud Enterprise Server is upgraded to 21.0.9.20, 22.2.10.35, 23.0.12.31, 24.0.12.30, 25.0.13.25, 26.0.13.22, 27.1.11.22, 28.0.14.13, 29.0.16.10, 30.0.17.5, 31.0.12 or 32.0.3
References
| Link | Resource |
|---|---|
| https://github.com/nextcloud/security-advisories/security/advisories/GHSA-285v-p9x9-cjhj | Vendor Advisory |
| https://github.com/nextcloud/server/pull/56982 | Issue Tracking Patch |
| https://hackerone.com/reports/3425534 | Permissions Required |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
04 Jun 2026, 16:51
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Nextcloud nextcloud Server
Nextcloud |
|
| References | () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-285v-p9x9-cjhj - Vendor Advisory | |
| References | () https://github.com/nextcloud/server/pull/56982 - Issue Tracking, Patch | |
| References | () https://hackerone.com/reports/3425534 - Permissions Required | |
| CPE | cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:* cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:* |
01 Jun 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-01 19:16
Updated : 2026-06-04 16:51
NVD link : CVE-2026-45810
Mitre link : CVE-2026-45810
CVE.ORG link : CVE-2026-45810
JSON object : View
Products Affected
nextcloud
- nextcloud_server
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
