Skip to content
Critical Authentication Bypass Vulnerabilities in Nextcloud for Fedora 44

Critical Authentication Bypass Vulnerabilities in Nextcloud for Fedora 44

First seen 17 Jun 2026, 15:59 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 18, 2026 at 15:27 UTC
  • CVE-2026-45690 allows bypassing two-factor authentication in Nextcloud.
  • Multiple vulnerabilities disclosed in Nextcloud version 33.0.5 affect Fedora systems.
  • Immediate patching is recommended to prevent unauthorized access and data breaches.

On June 17, 2026, Fedora released a security advisory for Nextcloud version 33.0.5, addressing multiple vulnerabilities. Key issues include CVE-2026-45690, an authentication bypass that allows unauthorized access by circumventing two-factor authentication. Other vulnerabilities include CVE-2026-45810, which enables information disclosure, and CVE-2026-45285, allowing unauthorized data access via unlisted public links. The vulnerabilities affect both Fedora and EPEL repositories. Users are urged to apply the updates immediately to mitigate risks. The advisory provides installation instructions using the 'dnf' update program. The vulnerabilities were published on June 1, 2026, indicating they have been known for a short period but could still pose significant risks if not addressed promptly.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 91d ago How this analysis works

Timeline

2026-06-01
CVE-2026-45690 published
Authentication bypass vulnerability disclosed, allowing unauthorized access by circumventing two-factor authentication.
Linuxsecurity
2026-06-01
CVE-2026-45691 published
Two-factor authentication bypass via session cookie vulnerability disclosed.
Linuxsecurity
2026-06-01
CVE-2026-45810 published
Information disclosure vulnerability via missing relation check in file disclosed.
Linuxsecurity
2026-06-01
CVE-2026-45285 published
Unauthorized data access and modification via unlisted public links vulnerability disclosed.
Linuxsecurity
2026-06-17
Fedora 44 security advisory released
Fedora issues an advisory for Nextcloud 33.0.5, urging users to apply updates to mitigate vulnerabilities.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track Fedora and CVE-2026-45285 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed