CVE-2026-45284

Source
https://cve.org/CVERecord?id=CVE-2026-45284
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45284.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-45284
Aliases
  • GHSA-79xf-ffj8-96fm
Published
2026-06-01T16:57:56Z
Modified
2026-08-12T03:51:36Z
Severity
  • 4.6 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L CVSS Calculator
Summary
Nextcloud: Wrong condition in the User OIDC app's LdapService allowed deleted LDAP users to authenticate
Details

Nextcloud is an open source content collaboration platform. From version 1.3.6 to before version 8.4.0, an improper check allowed users that where provided by LDAP to still authenticate towards user OIDC after they where deleted. This issue has been patched in version 8.4.0.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-284"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45284.json"
}
References

Affected packages

Git / github.com/nextcloud/user_oidc

Affected ranges

Type
GIT
Repo
https://github.com/nextcloud/user_oidc
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:nextcloud:user_oidc:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "1.3.6"
        },
        {
            "fixed": "8.4.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ]
}

Affected versions

v1.*
v1.3.6
v5.*
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v6.*
v6.0.0
v6.0.1
v6.1.0
v6.1.1
v6.1.2
v6.2.0
v6.2.1
v6.3.0
v6.3.1
v7.*
v7.0.0
v7.1.0
v7.2.0
v7.3.0
v7.3.1
v7.3.2
v7.4.0
v8.*
v8.0.0
v8.1.0
v8.2.0
v8.2.1
v8.2.2
v8.3.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45284.json"