Back cve.threatint.eu Nextcloud: ACL Rename Permission Bypass in Team Folders Allows Unauthorized F... CVE: New / 4h Nextcloud is an open source content collaboration platform.
Nextcloud is an open source content collaboration platform. From versions 17.0.0 to before 17.0.15, 18.0.0 to before 18.1.12, 19.0.0 to before 19.1.16, 20.0.0 to before 20.1.11, and 21.0.0 to before 21.0.4, a user with READ and CREATE permission, but no UPDATE permission for a team folder can rename files in the team folder. This issue has been patched in versions 17.0.15, 18.1.12, 19.1.16, 20.1.11, and 21.0.4.
PUBLISHED Reserved 2026-05-11 | Published 2026-06-01 | Updated 2026-06-01 | Assigner GitHub_M
MEDIUM: 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N Problem types CWE-284: Improper Access Control Product status >= 17.0.0, = 18.0.0, = 19.0.0, = 20.0.0, = 21.0.0, < 21.0.4 affected References github.com/...sories/security/advisories/GHSA-wx2x-822r-rvmf github.com/nextcloud/groupfolders/pull/4361 hackerone.com/reports/3540673 cve.org (CVE-2026-45264) nvd.nist.gov (CVE-2026-45264) Download JSON
CWE-284: Improper Access Control
github.com/...sories/security/advisories/GHSA-wx2x-822r-rvmf
github.com/nextcloud/groupfolders/pull/4361
hackerone.com/reports/3540673
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
