CVE-2026-45285
Nextcloud is an open source content collaboration platform. From versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, when a user shares a folder or file with a Nextcloud Team that includes an external member (a person added via email address who does not have a Nextcloud account), the system automatically creates a public link for that external member. This public link is not displayed in the share section of the folder, so the folder owner has no knowledge of its existence. It is sent via email to the external member.
Leer descripción completaMostrar menos
It grants the same permissions (read, write, delete, reshare, download) as the Team’s access. An attacker who receives or intercepts this link can access, modify, delete, reshare, and download all data in the shared folder without any further authentication. The folder owner cannot see or revoke the link through the normal sharing interface. This issue has been patched in versions 32.0.9 and 33.0.3.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N
- Puntuación base: 6.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.49%
- Percentil entre todas las CVEs puntuadas: 40
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-862
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-45285",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-45285",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-06-02T12:49:57.366871Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.4,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 1.2
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "nextcloud",
"product": "security-advisories",
"versions": [
{
"status": "affected",
"version": ">= 32.0.0, < 32.0.9"
},
{
"status": "affected",
"version": ">= 33.0.0, < 33.0.3"
}
]
}
]
}
],
"published": "2026-06-01T19:16:50.807",
"references": [
{
"url": "https://github.com/nextcloud/circles/pull/2454",
"tags": [
"Issue Tracking",
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/nextcloud/security-advisories/security/advisories/GHSA-r3xh-x86g-hw4m",
"tags": [
"Vendor Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://hackerone.com/reports/3625932",
"tags": [
"Permissions Required"
],
"source": "security-advisories@github.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-862"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Nextcloud is an open source content collaboration platform. From versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, when a user shares a folder or file with a Nextcloud Team that includes an external member (a person added via email address who does not have a Nextcloud account), the system automatically creates a public link for that external member. This public link is not displayed in the share section of the folder, so the folder owner has no knowledge of its existence. It is sent via email to the external member. It grants the same permissions (read, write, delete, reshare, download) as the Team’s access. An attacker who receives or intercepts this link can access, modify, delete, reshare, and download all data in the shared folder without any further authentication. The folder owner cannot see or revoke the link through the normal sharing interface. This issue has been patched in versions 32.0.9 and 33.0.3."
},
{
"lang": "es",
"value": "Nextcloud es una plataforma de colaboración de contenido de código abierto. Desde las versiones 32.0.0 hasta antes de la 32.0.9, y de la 33.0.0 hasta antes de la 33.0.3, cuando un usuario comparte una carpeta o archivo con un Equipo de Nextcloud que incluye un miembro externo (una persona añadida a través de una dirección de correo electrónico que no tiene una cuenta de Nextcloud), el sistema crea automáticamente un enlace público para ese miembro externo. Este enlace público no se muestra en la sección de compartir de la carpeta, por lo que el propietario de la carpeta no tiene conocimiento de su existencia. Se envía por correo electrónico al miembro externo. Otorga los mismos permisos (leer, escribir, eliminar, volver a compartir, descargar) que el acceso del Equipo. Un atacante que recibe o intercepta este enlace puede acceder, modificar, eliminar, volver a compartir y descargar todos los datos de la carpeta compartida sin ninguna autenticación adicional. El propietario de la carpeta no puede ver ni revocar el enlace a través de la interfaz de uso compartido normal. Este problema ha sido parcheado en las versiones 32.0.9 y 33.0.3."
}
],
"lastModified": "2026-07-22T08:10:00.117",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A4E473E0-CAC5-4C49-AA6A-84E16C6EAA13",
"versionEndExcluding": "32.0.9",
"versionStartIncluding": "32.0.0"
},
{
"criteria": "cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9B2B8E97-72E8-48AE-85F0-9FB5CE692F14",
"versionEndExcluding": "33.0.3",
"versionStartIncluding": "33.0.0"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E0868A4E-159B-40EC-9633-82B82E87ADA0",
"versionEndExcluding": "32.0.9",
"versionStartIncluding": "32.0.0"
},
{
"criteria": "cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1AD6566B-8299-4BDD-9ADD-8259D0EE4245",
"versionEndExcluding": "33.0.3",
"versionStartIncluding": "33.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}