Critical XSS Vulnerabilities in Nextcloud Affecting Fedora Users

Critical XSS Vulnerabilities in Nextcloud Affecting Fedora Users

First seen 25 Aug 2026, 10:17 UTC Linuxsecurity 60.6

Article Content

Browse articles
ThreatCluster

Multiple security vulnerabilities have been identified in Nextcloud versions running on Fedora, specifically CVE-2026-66010, CVE-2026-65903, and CVE-2026-59883. These vulnerabilities include a Cross-Site Scripting (XSS) attack vector that allows attackers to inject malicious content via custom element attributes and improper domain matching in cookies. The vulnerabilities were published between July 8 and July 24, 2026, and affect users of Nextcloud on Fedora systems. Administrators are urged to apply the latest updates to mitigate these risks. The advisory recommends using the 'dnf' update program to install necessary patches. The vulnerabilities could potentially lead to unauthorized access to sensitive information and compromise user data. Current status indicates that patches are available, but the risk remains until all systems are updated.

Key Points: • Three critical CVEs affect Nextcloud on Fedora: CVE-2026-66010, CVE-2026-65903, and CVE-2026-59883. • Vulnerabilities include XSS attacks and cookie injection risks that could expose sensitive data. • Patches are available, and users are advised to update their systems immediately.

Timeline

2026-07-08
CVE-2026-59883 published
Cross-host cookie disclosure and injection due to improper domain matching in CookieJar identified.
Linuxsecurity
2026-07-23
CVE-2026-65903 published
Security bypass allows injection of malicious content via DOMPurify confirmed.
Linuxsecurity
2026-07-24
CVE-2026-66010 published
XSS vulnerability via custom element attribute bypass reported.
Linuxsecurity
2026-08-25
Security advisories released
Fedora issues advisories for Nextcloud vulnerabilities, urging users to update immediately.
Linuxsecurity