Skip to content
CVE-2026-45264 - Exploits & Severity

CVE-2026-45264 - Exploits & Severity

Feedly June 1, 2026

Nextcloud is an open source content collaboration platform. From versions 17.0.0 to before 17.0.15, 18.0.0 to before 18.1.12, 19.0.0 to before 19.1.16, 20.0.0 to before 20.1.11, and 21.0.0 to before 21.0.4, a user with READ and CREATE permission, but no UPDATE permission for a team folder can rename files in the team folder. This issue has been patched in versions 17.0.15, 18.1.12, 19.1.16, 20.1.11, and 21.0.4.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Feedly found the first article mentioning CVE-2026-45264 . See article

NVD published the first details for CVE-2026-45264

A CVSS base score of 4.3 has been assigned.

CVE-2026-45264 | Nextcloud Team Folders up to 21.0.3 access control (GHSA-wx2x-822r-rvmf)

CVE-2026-45264: Nextcloud: ACL Rename Permission Bypass in Team Folders Allows Unauthorized File Renames [MEDIUM] CVSS 4.3

Nextcloud: ACL Rename Permission Bypass in Team Folders Allows Unauthorized F...

Collect, analyze, and vulnerability reports faster using AI

Extracted Entities