CVE-2026-45275

Source
https://cve.org/CVERecord?id=CVE-2026-45275
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45275.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-45275
Aliases
  • GHSA-v8q8-w6c3-3gv9
Published
2026-06-01T16:51:22.429Z
Modified
2026-07-24T03:56:54.926568866Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Nextcloud: Authorization bypass in approval feature allows unauthorized file sharing with approvers
Details

Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, a privilege escalation vulnerability exists in the Approval app that allows a user without sharing permissions to force the system to share a file with approvers. This results in an authorization bypass and privilege escalation, allowing unauthorized distribution of restricted files. This issue has been patched in version 2.7.2.

Database specific
{
    "cwe_ids": [
        "CWE-285"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45275.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/nextcloud/approval

Affected ranges

Type
GIT
Repo
https://github.com/nextcloud/approval
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "cpe": "cpe:2.3:a:nextcloud:approval:*:*:*:*:*:nextcloud:*:*",
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.7.2"
        }
    ]
}

Affected versions

v0.*
v0.0.3-2-nightly
v0.0.3-3-nightly
v0.0.3-4-nightly
v0.0.3-5-nightly
v0.0.4-1-nightly
v0.0.4-2-nightly
v0.0.6
v0.0.7
v0.0.8
v0.0.9
v1.*
v1.0.0
v1.0.1
v1.0.10
v1.0.10-2-nightly
v1.0.10-3-nightly
v1.0.11
v1.0.12
v1.0.13
v1.0.14
v1.0.2
v1.0.3
v1.0.4
v1.0.4-1-nightly
v1.0.5-1-nightly
v1.0.5-2-nightly
v1.0.5-3-nightly
v1.0.5-4-nightly
v1.0.5-5-nightly
v1.0.5-6-nightly
v1.0.6
v1.0.7
v1.0.7-1-nightly
v1.0.7-2-nightly
v1.0.7-3-nightly
v1.0.7-4-nightly
v1.0.8
v1.0.8-1-nightly
v1.0.9
v1.1.0
v1.1.1
v1.2.0
v1.3.0
v2.*
v2.0.0
v2.1.0
v2.2.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.7.0
v2.7.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45275.json"