Skip to content
Critical RCE and DoS Vulnerabilities in Nextcloud Affect Fedora Users

Critical RCE and DoS Vulnerabilities in Nextcloud Affect Fedora Users

First seen 10 May 2026, 11:02 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster May 11, 2026 at 10:33 UTC
  • Multiple critical vulnerabilities in Nextcloud 33.0.3 affect Fedora 42 and 44 users.
  • CVE-2026-33937 allows remote code execution via crafted Abstract Syntax Tree objects.
  • Administrators are advised to update using 'dnf' to mitigate these vulnerabilities.

On May 2, 2026, Fedora released an advisory for Nextcloud version 33.0.3, addressing multiple critical vulnerabilities, including remote code execution (RCE) and denial of service (DoS) issues. The vulnerabilities are linked to the Handlebars.js templating engine, with CVEs including CVE-2026-33937, CVE-2026-33939, CVE-2026-33940, CVE-2026-33916, and CVE-2026-33938, all published on March 27, 2026. Attack vectors involve crafted Abstract Syntax Tree objects and malformed decorator syntax, allowing for arbitrary code execution and service disruption. Users of Fedora 42 and 44 are specifically affected, and administrators are urged to apply the patches using the 'dnf' update program. The vulnerabilities pose a significant risk due to their potential for exploitation in live environments. As of now, no active exploitation has been reported, but the existence of proof-of-concept (PoC) exploits raises concerns.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 132d ago How this analysis works

Timeline

2026-03-27
Multiple CVEs published for Nextcloud vulnerabilities
CVE-2026-33916, CVE-2026-33937, CVE-2026-33938, CVE-2026-33939, and CVE-2026-33940 were published, detailing critical vulnerabilities in Nextcloud's Handlebars.js.
Linuxsecurity
2026-03-27
CVE-2026-33939 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-03-27
CVE-2026-33940 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-03-27
CVE-2026-33916 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-03-27
CVE-2026-33938 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-03-28
First public PoC for CVE-2026-33937 released
A proof-of-concept exploit for the remote code execution vulnerability was made publicly available, increasing the urgency for patching.
Linuxsecurity
2026-05-02
Fedora releases advisory for Nextcloud 33.0.3
Fedora issued a critical update for Nextcloud 33.0.3, addressing multiple vulnerabilities and urging users to upgrade immediately.
Linuxsecurity

More articles in this cluster (3)

Following this threat?

Track Fedora and CVE-2026-33916 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed