CVE-2026-45159

Source
https://cve.org/CVERecord?id=CVE-2026-45159
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45159.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-45159
Aliases
  • GHSA-p3qw-7gwx-wg24
Published
2026-06-01T16:39:38.836Z
Modified
2026-07-24T03:56:45.314673285Z
Severity
  • 3.5 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N CVSS Calculator
Summary
Nextcloud: Files drop share links for end-to-end encrypted folders allowed to drop files into other folders of the share owner
Details

Nextcloud is an open source content collaboration platform. From versions 1.15.0 to before 1.15.4, 1.16.0 to before 1.16.3, 1.17.0 to before 1.17.1, and 1.18.0 to before 1.18.1, a malicious user with access to an end-to-end encrypted files drop link was able to also drop files into other end-to-end encrypted folders of the share owner. Reading and modifying of other files was not possible. This issue has been patched in versions 1.15.4, 1.16.3, 1.17.1, 1.18.1, and 2.0.0-rc.7.

Database specific
{
    "cwe_ids": [
        "CWE-639"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45159.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/nextcloud/end_to_end_encryption

Affected ranges

Type
GIT
Repo
https://github.com/nextcloud/end_to_end_encryption
Events
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "1.15.0"
        },
        {
            "fixed": "1.15.4"
        },
        {
            "introduced": "1.16.0"
        },
        {
            "fixed": "1.16.3"
        },
        {
            "introduced": "1.17.0"
        },
        {
            "fixed": "1.17.1"
        },
        {
            "introduced": "1.18.0"
        },
        {
            "fixed": "1.18.1"
        }
    ]
}

Affected versions

v1.*
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.16.0
v1.16.1
v1.16.2
v1.17.0
v1.18.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45159.json"