Skip to content
Nextcloud: ACL Rename Permission Bypass in Team Folders Allows Unauthorized F... CVE: New / 4h Nextcloud is an open source content collaboration platform.

Nextcloud: ACL Rename Permission Bypass in Team Folders Allows Unauthorized F... CVE: New / 4h Nextcloud is an open source content collaboration platform.

cve.threatint.eu June 1, 2026

Nextcloud is an open source content collaboration platform. From versions 17.0.0 to before 17.0.15, 18.0.0 to before 18.1.12, 19.0.0 to before 19.1.16, 20.0.0 to before 20.1.11, and 21.0.0 to before 21.0.4, a user with READ and CREATE permission, but no UPDATE permission for a team folder can rename files in the team folder. This issue has been patched in versions 17.0.15, 18.1.12, 19.1.16, 20.1.11, and 21.0.4.

PUBLISHED Reserved 2026-05-11 | Published 2026-06-01 | Updated 2026-06-01 | Assigner GitHub_M

MEDIUM: 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N Problem types CWE-284: Improper Access Control Product status >= 17.0.0, = 18.0.0, = 19.0.0, = 20.0.0, = 21.0.0, < 21.0.4 affected References github.com/...sories/security/advisories/GHSA-wx2x-822r-rvmf github.com/nextcloud/groupfolders/pull/4361 hackerone.com/reports/3540673 cve.org (CVE-2026-45264) nvd.nist.gov (CVE-2026-45264) Download JSON

CWE-284: Improper Access Control

github.com/...sories/security/advisories/GHSA-wx2x-822r-rvmf

github.com/nextcloud/groupfolders/pull/4361

hackerone.com/reports/3540673

cve.org (CVE-2026-45264)

nvd.nist.gov (CVE-2026-45264)

Extracted Entities