CVE-2026-45810Medium· 6.8▾ SunlitNextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.12, and 32.0.0 to before 32.0.3, a missing check of a relation allowed authenticated users with access to any file commen…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 37.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 23.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.12, and 32.0.0 to before 32.0.3, a missing check of a relation allowed authenticated users with access to any file comment, to read the content of all comments. It is recommended that the Nextcloud Server is upgraded to 31.0.12 or 32.0.3. It is recommended that the Nextcloud Enterprise Server is upgraded to 21.0.9.20, 22.2.10.35, 23.0.12.31, 24.0.12.30, 25.0.13.25, 26.0.13.22, 27.1.11.22, 28.0.14.13, 29.0.16.10, 30.0.17.5, 31.0.12 or 32.0.3
nextcloud_server >= 31.0.0, < 31.0.12nextcloud_server >= 32.0.0, < 32.0.3nextcloud_server >= 21.0.0, < 21.0.9.20nextcloud_server >= 22.0.0, < 22.2.10.35nextcloud_server >= 23.0.0, < 23.0.12.31nextcloud_server >= 24.0.0, < 24.0.12.30nextcloud_server >= 25.0.0, < 25.0.13.25nextcloud_server >= 26.0.0, < 26.0.13.22nextcloud_server >= 27.0.0, < 27.1.11.22nextcloud_server >= 28.0.0, < 28.0.14.13nextcloud_server >= 29.0.0, < 29.0.16.10nextcloud_server >= 30.0.0, < 30.0.17.5Upgrade past the affected range:
nextcloud_server 32.0.3Connected by shared product, vendor, weakness, or advisory.
CVE-2026-68493Low· 3.1After guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships for a circle they are not a member of.
CVE-2026-45691Medium· 5.9Nextcloud is an open source content collaboration platform
CVE-2026-45690Medium· 5.9Nextcloud is an open source content collaboration platform
CVE-2026-45285Medium· 6.4Nextcloud is an open source content collaboration platform
CVE-2021-46416High· 8.1Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.
CVE-2025-14459High· 8.5A flaw was found in KubeVirt Containerized Data Importer (CDI)