« Volver al listado

CVE-2026-45159

Estado: AplazadaBaja (3.5)—

Nextcloud is an open source content collaboration platform. From versions 1.15.0 to before 1.15.4, 1.16.0 to before 1.16.3, 1.17.0 to before 1.17.1, and 1.18.0 to before 1.18.1, a malicious user with access to an end-to-end encrypted files drop link was able to also drop files into other end-to-end encrypted folders of the share owner. Reading and modifying of other files was not possible. This issue has been patched in versions 1.15.4, 1.16.3, 1.17.1, 1.18.1, and 2.0.0-rc.7.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-45159",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-45159",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-01T19:30:14.088508Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.5,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.1
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "nextcloud",
          "product": "security-advisories",
          "versions": [
            {
              "status": "affected",
              "version": ">= 1.15.0, < 1.15.4"
            },
            {
              "status": "affected",
              "version": ">= 1.16.0, < 1.16.3"
            },
            {
              "status": "affected",
              "version": ">= 1.17.0, < 1.17.1"
            },
            {
              "status": "affected",
              "version": ">= 1.18.0, < 1.18.1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-06-01T17:17:09.550",
  "references": [
    {
      "url": "https://github.com/nextcloud/end_to_end_encryption/pull/1395",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/nextcloud/security-advisories/security/advisories/GHSA-p3qw-7gwx-wg24",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://hackerone.com/reports/3304830",
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-639"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Nextcloud is an open source content collaboration platform. From versions 1.15.0 to before 1.15.4, 1.16.0 to before 1.16.3, 1.17.0 to before 1.17.1, and 1.18.0 to before 1.18.1, a malicious user with access to an end-to-end encrypted files drop link was able to also drop files into other end-to-end encrypted folders of the share owner. Reading and modifying of other files was not possible. This issue has been patched in versions 1.15.4, 1.16.3, 1.17.1, 1.18.1, and 2.0.0-rc.7."
    },
    {
      "lang": "es",
      "value": "Nextcloud es una plataforma de colaboración de contenido de código abierto. Desde las versiones 1.15.0 hasta antes de la 1.15.4, de la 1.16.0 hasta antes de la 1.16.3, de la 1.17.0 hasta antes de la 1.17.1, y de la 1.18.0 hasta antes de la 1.18.1, un usuario malicioso con acceso a un enlace de carga de archivos cifrados de extremo a extremo pudo también cargar archivos en otras carpetas cifradas de extremo a extremo del propietario del recurso compartido. La lectura y modificación de otros archivos no fue posible. Este problema ha sido parcheado en las versiones 1.15.4, 1.16.3, 1.17.1, 1.18.1 y 2.0.0-rc.7."
    }
  ],
  "lastModified": "2026-07-22T07:10:00.107",
  "sourceIdentifier": "security-advisories@github.com"
}