CVE-2026-45691Medium· 5.9▾ SunlitNextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, a pre-2FA session cookie (created after successful password authentication but before TOT…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 23.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, a pre-2FA session cookie (created after successful password authentication but before TOTP completion) could be reused as a Bearer token to authenticate against DAV endpoints, granting read/write access and bypassing mandatory two-factor authentication. It is recommended that the Nextcloud Server is upgraded to 33.0.3 or 32.0.9. It is recommended that the Nextcloud Enterprise Server is upgraded to 33.0.3, 32.0.9, 31.0.14.5, 30.0.17.9 or 29.0.16.16
nextcloud_server >= 32.0.0, < 32.0.9nextcloud_server >= 33.0.0, < 33.0.3nextcloud_server >= 29.0.0, < 29.0.16.16nextcloud_server >= 30.0.0, < 30.0.17.9nextcloud_server >= 31.0.0, < 31.0.14.5Upgrade past the affected range:
nextcloud_server 33.0.3Connected by shared product, vendor, weakness, or advisory.
CVE-2026-45690Medium· 5.9Nextcloud is an open source content collaboration platform
CVE-2026-82980Medium· 6.3Any authenticated user can lock or unlock files they do not own by targeting absolute WebDAV paths of other users
CVE-2026-45810Medium· 6.8Nextcloud is an open source content collaboration platform
CVE-2026-45285Medium· 6.4Nextcloud is an open source content collaboration platform
CVE-2023-49105Critical· 9.8An issue was discovered in ownCloud owncloud/core before 10.13.1
CVE-2019-1946Medium· 6.5A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to bypass authentication and get limited access to the web-based management int…