Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, authenticated users can check if arbitrary files are associated with specific approval workflows where they can request approval. This issue has been patched in version 2.7.2.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
NVD published the first details for CVE-2026-45277
A CVSS base score of 3.3 has been assigned.
Feedly found the first article mentioning CVE-2026-45277 . See article
Webinar tomorrow: From alert to resolution in network incident response
CVE-2026-45277 | Nextcloud Approval up to 2.7.1 information disclosure (GHSA-h7gm-vgxr-9hcw)
CVE-2026-45277: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in nextcloud security-advisories
Collect, analyze, and vulnerability reports faster using AI
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
