CVE-2026-45810

Source
https://cve.org/CVERecord?id=CVE-2026-45810
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45810.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-45810
Aliases
Published
2026-06-01T17:13:21.681Z
Modified
2026-07-15T01:49:11.171930757Z
Severity
  • 6.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N CVSS Calculator
Summary
Nextcloud: Propfind requests for file comments allowed to load comments for other files
Details

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.12, and 32.0.0 to before 32.0.3, a missing check of a relation allowed authenticated users with access to any file comment, to read the content of all comments. It is recommended that the Nextcloud Server is upgraded to 31.0.12 or 32.0.3. It is recommended that the Nextcloud Enterprise Server is upgraded to 21.0.9.20, 22.2.10.35, 23.0.12.31, 24.0.12.30, 25.0.13.25, 26.0.13.22, 27.1.11.22, 28.0.14.13, 29.0.16.10, 30.0.17.5, 31.0.12 or 32.0.3

Database specific
{
    "cwe_ids": [
        "CWE-639"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45810.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/nextcloud/server

Affected ranges

Type
GIT
Repo
https://github.com/nextcloud/server
Events
Database specific
{
    "cpe": [
        "cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*",
        "cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "31.0.0"
        },
        {
            "fixed": "31.0.12"
        },
        {
            "introduced": "32.0.0"
        },
        {
            "fixed": "32.0.3"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

v31.*
v31.0.0
v31.0.1
v31.0.10
v31.0.10rc1
v31.0.10rc2
v31.0.11
v31.0.11rc1
v31.0.11rc2
v31.0.12rc1
v31.0.12rc2
v31.0.12rc3
v31.0.1rc1
v31.0.1rc2
v31.0.2
v31.0.2rc1
v31.0.3
v31.0.3rc1
v31.0.3rc2
v31.0.4
v31.0.4rc1
v31.0.5
v31.0.5rc1
v31.0.6
v31.0.6rc1
v31.0.6rc2
v31.0.7
v31.0.7rc1
v31.0.8
v31.0.8rc1
v31.0.9
v31.0.9rc1
v32.*
v32.0.0
v32.0.1
v32.0.1rc1
v32.0.1rc2
v32.0.2
v32.0.2rc1
v32.0.2rc2
v32.0.3rc1
v32.0.3rc2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45810.json"