CVE-2026-45279

Source
https://cve.org/CVERecord?id=CVE-2026-45279
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45279.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-45279
Aliases
  • GHSA-j33j-qph5-4wch
Published
2026-06-01T16:52:18.958Z
Modified
2026-07-15T01:49:21.919087078Z
Severity
  • 4.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Nextcloud: Limited path traversal via template API if using `{lang}` in config
Details

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.14, and 32.0.0 to before 32.0.4, if {lang} is used in the template directory config value, non-admin users can in some cases copy arbitrary files (depending on unix permissions) into their own Nextcloud directory via a path traversal. It is recommended that the Nextcloud Server is upgraded to 32.0.4, 31.0.14. It is recommended that the Nextcloud Enterprise Server is upgraded to 32.0.4, 31.0.14, 30.0.17.7, 29.0.17.12, 28.0.14.15

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45279.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-22"
    ]
}
References

Affected packages

Git / github.com/nextcloud/server

Affected ranges

Type
GIT
Repo
https://github.com/nextcloud/server
Events
Database specific
{
    "cpe": [
        "cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*",
        "cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "31.0.0"
        },
        {
            "fixed": "31.0.14"
        },
        {
            "introduced": "32.0.0"
        },
        {
            "fixed": "32.0.4"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

v31.*
v31.0.0
v31.0.1
v31.0.10
v31.0.10rc1
v31.0.10rc2
v31.0.11
v31.0.11rc1
v31.0.11rc2
v31.0.12
v31.0.12rc1
v31.0.12rc2
v31.0.12rc3
v31.0.13
v31.0.13rc1
v31.0.14rc1
v31.0.1rc1
v31.0.1rc2
v31.0.2
v31.0.2rc1
v31.0.3
v31.0.3rc1
v31.0.3rc2
v31.0.4
v31.0.4rc1
v31.0.5
v31.0.5rc1
v31.0.6
v31.0.6rc1
v31.0.6rc2
v31.0.7
v31.0.7rc1
v31.0.8
v31.0.8rc1
v31.0.9
v31.0.9rc1
v32.*
v32.0.0
v32.0.1
v32.0.1rc1
v32.0.1rc2
v32.0.2
v32.0.2rc1
v32.0.2rc2
v32.0.3
v32.0.3rc1
v32.0.3rc2
v32.0.4rc1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45279.json"