nextcloud_server vulnerabilities
CVEs whose affected-version data names the nextcloud_server package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-45810Medium· 6.8Nextcloud is an open source content collaboration platform
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.12, and 32.0.0 to before 32.0.3, a missing check of a relation allowed authenticated users with access to any file commen…
CVE-2026-45691Medium· 5.9Nextcloud is an open source content collaboration platform
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, a pre-2FA session cookie (created after successful password authentication but before TOT…
CVE-2026-45690Medium· 5.9Nextcloud is an open source content collaboration platform
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, an authentication bypass vulnerability allowed attackers with knowledge of a user's passw…
CVE-2026-45285Medium· 6.4Nextcloud is an open source content collaboration platform
Nextcloud is an open source content collaboration platform. From versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, when a user shares a folder or file with a Nextcloud Team that includes an external member (a person added vi…