Nextcloud CVE-2026-45277: Low-Severity Information Disclosure Vulnerability
Article Content
- •CVE-2026-45277 is a low-severity vulnerability in Nextcloud versions before 2.7.2.
- •Authenticated users can exploit this flaw to check file approval workflows, risking sensitive information exposure.
- •Nextcloud version 2.7.2 addresses this vulnerability; users must apply the update manually.
CVE-2026-45277 is a low-severity vulnerability affecting Nextcloud versions prior to 2.7.2. Authenticated users could exploit this flaw to determine if arbitrary files are linked to specific approval workflows, potentially exposing sensitive metadata. The vulnerability has a CVSS 3.1 base score of 3.3, indicating limited impact on confidentiality, integrity, and availability. It does not allow for modification or denial of service. The issue has been patched in Nextcloud version 2.7.2, and users are advised to upgrade to this version or later. There are currently no known exploits in the wild. As this is not a cloud service, users must manually apply the update. The vulnerability was published on June 1, 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track CVE-2026-45277 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…