Nextcloud CVE-2026-45277: Low-Severity Information Disclosure Vulnerability

Nextcloud CVE-2026-45277: Low-Severity Information Disclosure Vulnerability

1 Jun 2026 Feedlyradar.offseq.comnvd.nist.govvuldb.comcve.report 86% similarity 30.9
Share:

Article Content

Browse articles
ThreatCluster

CVE-2026-45277 is a low-severity vulnerability affecting Nextcloud versions prior to 2.7.2. Authenticated users could exploit this flaw to determine if arbitrary files are linked to specific approval workflows, potentially exposing sensitive metadata. The vulnerability has a CVSS 3.1 base score of 3.3, indicating limited impact on confidentiality, integrity, and availability. It does not allow for modification or denial of service. The issue has been patched in Nextcloud version 2.7.2, and users are advised to upgrade to this version or later. There are currently no known exploits in the wild. As this is not a cloud service, users must manually apply the update. The vulnerability was published on June 1, 2026.

Key Points: • CVE-2026-45277 is a low-severity vulnerability in Nextcloud versions before 2.7.2. • Authenticated users can exploit this flaw to check file approval workflows, risking sensitive information exposure. • Nextcloud version 2.7.2 addresses this vulnerability; users must apply the update manually.

ThreatCluster AI

Timeline

2026-06-01
CVE-2026-45277 published
Nextcloud disclosed a low-severity information disclosure vulnerability affecting versions prior to 2.7.2.
radar.offseq.com
2026-06-01
Vulnerability patched in Nextcloud 2.7.2
Nextcloud released version 2.7.2, which addresses CVE-2026-45277, preventing unauthorized information disclosure.
nvd.nist.gov
2026-06-01
No known exploits reported
As of the publication date, there are no known exploits of CVE-2026-45277 in the wild.
Feedly

Community

Browse all →