Skip to content
CVE-2026-45264: Nextcloud: ACL Rename Permission Bypass in Team Folders Allows Unauthorized File Renames [MEDIUM] CVSS 4.3 Exploit Intelligence — Recent CVEs / 3h Nextcloud is an open source content collaboration platform. From versions 17.0.0 to before 17.0.15, 18.0.0 to before 18.1.12, 19.0.0 to before 19.1.16, 20.0.0 to before 20.1.11, and 21.0.0 to before 21.0.4, a user with READ and CREATE permission, but no UPDATE permission for a team folder can rename

CVE-2026-45264: Nextcloud: ACL Rename Permission Bypass in Team Folders Allows Unauthorized File Renames [MEDIUM] CVSS 4.3 Exploit Intelligence — Recent CVEs / 3h Nextcloud is an open source content collaboration platform. From versions 17.0.0 to before 17.0.15, 18.0.0 to before 18.1.12, 19.0.0 to before 19.1.16, 20.0.0 to before 20.1.11, and 21.0.0 to before 21.0.4, a user with READ and CREATE permission, but no UPDATE permission for a team folder can rename

exploit-intel.com June 1, 2026

Extracted Entities