Critical RCE and DoS Vulnerabilities in Nextcloud Affect Fedora Users

Critical RCE and DoS Vulnerabilities in Nextcloud Affect Fedora Users

First seen 10 May 2026, 11:02 UTC Linuxsecurity 94% similarity 70.5

Article Content

Browse articles
ThreatCluster

On May 2, 2026, Fedora released an advisory for Nextcloud version 33.0.3, addressing multiple critical vulnerabilities, including remote code execution (RCE) and denial of service (DoS) issues. The vulnerabilities are linked to the Handlebars.js templating engine, with CVEs including CVE-2026-33937, CVE-2026-33939, CVE-2026-33940, CVE-2026-33916, and CVE-2026-33938, all published on March 27, 2026. Attack vectors involve crafted Abstract Syntax Tree objects and malformed decorator syntax, allowing for arbitrary code execution and service disruption. Users of Fedora 42 and 44 are specifically affected, and administrators are urged to apply the patches using the 'dnf' update program. The vulnerabilities pose a significant risk due to their potential for exploitation in live environments. As of now, no active exploitation has been reported, but the existence of proof-of-concept (PoC) exploits raises concerns.

Key Points: • Multiple critical vulnerabilities in Nextcloud 33.0.3 affect Fedora 42 and 44 users. • CVE-2026-33937 allows remote code execution via crafted Abstract Syntax Tree objects. • Administrators are advised to update using 'dnf' to mitigate these vulnerabilities.

ThreatCluster AI

Timeline

2026-03-27
Multiple CVEs published for Nextcloud vulnerabilities
CVE-2026-33916, CVE-2026-33937, CVE-2026-33938, CVE-2026-33939, and CVE-2026-33940 were published, detailing critical vulnerabilities in Nextcloud's Handlebars.js.
Linuxsecurity
2026-03-27
CVE-2026-33939 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-03-27
CVE-2026-33940 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-03-27
CVE-2026-33916 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-03-27
CVE-2026-33938 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-03-28
First public PoC for CVE-2026-33937 released
A proof-of-concept exploit for the remote code execution vulnerability was made publicly available, increasing the urgency for patching.
Linuxsecurity
2026-05-02
Fedora releases advisory for Nextcloud 33.0.3
Fedora issued a critical update for Nextcloud 33.0.3, addressing multiple vulnerabilities and urging users to upgrade immediately.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story