CVE-2026-45283

Source
https://cve.org/CVERecord?id=CVE-2026-45283
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45283.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-45283
Aliases
  • GHSA-4chh-6mhf-p4jj
Published
2026-06-01T16:53:50.656Z
Modified
2026-08-12T03:51:09.348330657Z
Severity
  • 6.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
Summary
Nextcloud: Files Lock app allows users to lock and unlock files of other users
Details

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.2, and 33.0.0 to before 33.0.1, the files_lock app did not properly validate the ownership of files when processing DAV lock and unlock requests. An authenticated user could lock or unlock files belonging to other users by targeting their absolute WebDAV paths. Additionally, lock tokens were disclosed to unauthorized callers in error responses, allowing attackers to remove token-based locks placed by other users' client applications. It is recommended that the Nextcloud Server is upgraded to 32.0.2 or 33.0.1. It is recommended that the Nextcloud Enterprise Server is upgraded to 31.0.14.4 or 32.0.2 or 33.0.1

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45283.json",
    "cwe_ids": [
        "CWE-287"
    ],
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/nextcloud/files_lock

Affected ranges

Type
GIT
Repo
https://github.com/nextcloud/files_lock
Events
Database specific
Show details
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "32.0.0"
        },
        {
            "fixed": "32.0.2"
        },
        {
            "introduced": "33.0.0"
        },
        {
            "fixed": "33.0.1"
        }
    ]
}
Type
GIT
Repo
https://github.com/nextcloud/server
Events
Database specific
Show details
{
    "cpe": [
        "cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*",
        "cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*"
    ],
    "source": "CPE_RANGE",
    "extracted_events": [
        {
            "introduced": "32.0.0"
        },
        {
            "fixed": "32.0.2"
        },
        {
            "introduced": "33.0.0"
        },
        {
            "fixed": "33.0.1"
        }
    ]
}

Affected versions

v32.*
v32.0.0
v32.0.1
v32.0.1rc1
v32.0.1rc2
v32.0.2rc1
v32.0.2rc2
v33.*
v33.0.0
v33.0.1rc1
v33.0.1rc2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45283.json"