{"id":"CVE-2026-77169","title":"A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed API/REST-only delegated administrators to bypass folder-level authorization controls","summary":"A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed API/REST-only delegated administrators to bypass folder-level authorization controls. The workspace app enables orga…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-284"],"vendor":"Nextcloud","product":"Team Folders","affected":["team_folders >= 13.0.0 < 22.0.0"],"published":"2026-09-18","updated":"2026-09-18","sourceUpdated":"2026-09-18T20:17:22.383","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-77169","references":[{"url":"https://hackerone.com/reports/3674940","label":"support@hackerone.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-18T19:42:21.795020Z"},"epss":0.00241,"epssPercentile":0.15585,"ingestedAt":"2026-09-18T01:33:24.272Z","slug":"CVE-2026-77169","body":"## Overview\n\nA vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed API/REST-only delegated administrators to bypass folder-level authorization controls. The workspace app enables organizations to delegate limited administrative privileges for team folder management via API/REST only, restricting access to folders for which the admin has advanced permissions.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}