Linuxsecurity Critical Authentication Bypass Vulnerabilities in Nextcloud for Fedora 44
Article Content
- •CVE-2026-45690 allows bypassing two-factor authentication in Nextcloud.
- •Multiple vulnerabilities disclosed in Nextcloud version 33.0.5 affect Fedora systems.
- •Immediate patching is recommended to prevent unauthorized access and data breaches.
On June 17, 2026, Fedora released a security advisory for Nextcloud version 33.0.5, addressing multiple vulnerabilities. Key issues include CVE-2026-45690, an authentication bypass that allows unauthorized access by circumventing two-factor authentication. Other vulnerabilities include CVE-2026-45810, which enables information disclosure, and CVE-2026-45285, allowing unauthorized data access via unlisted public links. The vulnerabilities affect both Fedora and EPEL repositories. Users are urged to apply the updates immediately to mitigate risks. The advisory provides installation instructions using the 'dnf' update program. The vulnerabilities were published on June 1, 2026, indicating they have been known for a short period but could still pose significant risks if not addressed promptly.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Fedora and CVE-2026-45285 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…