CVE-2026-45284

Source
https://cve.org/CVERecord?id=CVE-2026-45284
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45284.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-45284
Aliases
  • GHSA-79xf-ffj8-96fm
Published
2026-06-01T16:57:56.210Z
Modified
2026-07-15T01:49:06.335248327Z
Severity
  • 4.6 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L CVSS Calculator
Summary
Nextcloud: Wrong condition in the User OIDC app's LdapService allowed deleted LDAP users to authenticate
Details

Nextcloud is an open source content collaboration platform. From version 1.3.6 to before version 8.4.0, an improper check allowed users that where provided by LDAP to still authenticate towards user OIDC after they where deleted. This issue has been patched in version 8.4.0.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45284.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-284"
    ]
}
References

Affected packages

Git / github.com/nextcloud/user_oidc

Affected ranges

Type
GIT
Repo
https://github.com/nextcloud/user_oidc
Events
Database specific
{
    "cpe": "cpe:2.3:a:nextcloud:user_oidc:*:*:*:*:*:*:*:*",
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ],
    "extracted_events": [
        {
            "introduced": "1.3.6"
        },
        {
            "fixed": "8.4.0"
        }
    ]
}

Affected versions

v1.*
v1.3.6
v5.*
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v6.*
v6.0.0
v6.0.1
v6.1.0
v6.1.1
v6.1.2
v6.2.0
v6.2.1
v6.3.0
v6.3.1
v7.*
v7.0.0
v7.1.0
v7.2.0
v7.3.0
v7.3.1
v7.3.2
v7.4.0
v8.*
v8.0.0
v8.1.0
v8.2.0
v8.2.1
v8.2.2
v8.3.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45284.json"