CVE-2026-45264

Source
https://cve.org/CVERecord?id=CVE-2026-45264
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45264.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-45264
Aliases
  • GHSA-wx2x-822r-rvmf
Published
2026-06-01T16:36:57.130Z
Modified
2026-07-24T03:56:47.239207759Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
Nextcloud: ACL Rename Permission Bypass in Team Folders Allows Unauthorized File Renames
Details

Nextcloud is an open source content collaboration platform. From versions 17.0.0 to before 17.0.15, 18.0.0 to before 18.1.12, 19.0.0 to before 19.1.16, 20.0.0 to before 20.1.11, and 21.0.0 to before 21.0.4, a user with READ and CREATE permission, but no UPDATE permission for a team folder can rename files in the team folder. This issue has been patched in versions 17.0.15, 18.1.12, 19.1.16, 20.1.11, and 21.0.4.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45264.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-284"
    ]
}
References

Affected packages

Git / github.com/nextcloud/groupfolders

Affected ranges

Type
GIT
Repo
https://github.com/nextcloud/groupfolders
Events
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "17.0.0"
        },
        {
            "fixed": "17.0.15"
        },
        {
            "introduced": "18.0.0"
        },
        {
            "fixed": "18.1.12"
        },
        {
            "introduced": "19.0.0"
        },
        {
            "fixed": "19.1.16"
        },
        {
            "introduced": "20.0.0"
        },
        {
            "fixed": "20.1.11"
        },
        {
            "introduced": "21.0.0"
        },
        {
            "fixed": "21.0.4"
        }
    ]
}

Affected versions

v17.*
v17.0.0
v17.0.1
v17.0.10
v17.0.11
v17.0.12
v17.0.13
v17.0.14
v17.0.2
v17.0.3
v17.0.4
v17.0.5
v17.0.6
v17.0.7
v17.0.8
v17.0.9
v18.*
v18.0.0
v18.0.1
v18.0.10
v18.0.2
v18.0.3
v18.0.4
v18.0.5
v18.0.6
v18.0.7
v18.0.8
v18.0.9
v18.1.0
v18.1.1
v18.1.10
v18.1.11
v18.1.2
v18.1.3
v18.1.4
v18.1.5
v18.1.6
v18.1.7
v18.1.8
v18.1.9
v20.*
v20.0.0
v20.0.1
v20.1.0
v20.1.1
v20.1.10
v20.1.2
v20.1.3
v20.1.4
v20.1.5
v20.1.7
v20.1.8
v20.1.9
v21.*
v21.0.0
v21.0.1
v21.0.2
v21.0.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45264.json"