---
id: CVE-2026-45284
title: Nextcloud is an open source content collaboration platform
summary: >-
  Nextcloud is an open source content collaboration platform. From version 1.3.6
  to before version 8.4.0, an improper check allowed users that where provided
  by LDAP to still authenticate towards user OIDC after they where deleted. This
  is…
severity: medium
cvss: 4.6
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L'
cwe:
  - CWE-284
vendor: nextcloud
product: user_oidc
affected:
  - 'user_oidc >= 1.3.6, < 8.4.0'
patched:
  - user_oidc 8.4.0
published: '2026-06-01'
updated: '2026-07-22'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-45284'
references:
  - url: >-
      https://github.com/nextcloud/security-advisories/security/advisories/GHSA-79xf-ffj8-96fm
    label: security-advisories@github.com
  - url: 'https://github.com/nextcloud/user_oidc/pull/1340'
    label: security-advisories@github.com
  - url: 'https://hackerone.com/reports/3554696'
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00193
epssPercentile: 0.093
ingestedAt: '2026-07-23T07:14:46.314Z'
---

## Overview

Nextcloud is an open source content collaboration platform. From version 1.3.6 to before version 8.4.0, an improper check allowed users that where provided by LDAP to still authenticate towards user OIDC after they where deleted. This issue has been patched in version 8.4.0.

## Affected

- `user_oidc >= 1.3.6, < 8.4.0`

## Remediation

Upgrade past the affected range:

- `user_oidc 8.4.0`
