Linuxsecurity
Critical Authentication Bypass Vulnerabilities in Nextcloud for Fedora 44
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
On June 17, 2026, Fedora released a security advisory for Nextcloud version 33.0.5, addressing multiple vulnerabilities. Key issues include CVE-2026-45690, an authentication bypass that allows unauthorized access by circumventing two-factor authentication. Other vulnerabilities include CVE-2026-45810, which enables information disclosure, and CVE-2026-45285, allowing unauthorized data access via unlisted public links. The vulnerabilities affect both Fedora and EPEL repositories. Users are urged to apply the updates immediately to mitigate risks. The advisory provides installation instructions using the 'dnf' update program. The vulnerabilities were published on June 1, 2026, indicating they have been known for a short period but could still pose significant risks if not addressed promptly.
Key Points: • CVE-2026-45690 allows bypassing two-factor authentication in Nextcloud. • Multiple vulnerabilities disclosed in Nextcloud version 33.0.5 affect Fedora systems. • Immediate patching is recommended to prevent unauthorized access and data breaches.