CVE-2026-45690Patch(nextcloud / nextcloud_server)

LOWCVSS 5.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nextcloud nextcloud_server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, an authentication bypass vulnerability allowed attackers with knowledge of a user's password to circumvent two-factor authentication (2FA) protections. When a user initiated login with valid credentials on a 2FA-enabled account, the system created a temporary session token before enforcing the second factor challenge. This token could be extracted and replayed via HTTP Basic Authentication to gain unauthorized access to authenticated endpoints. It is recommended that the Nextcloud Server is upgraded to 33.0.3 or 32.0.9. It is recommended that the Nextcloud Enterprise Server is upgraded to 33.0.3, 32.0.9, 31.0.14.5, 30.0.17.9 or 29.0.16.16

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nextcloud_server

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
nextcloud_server

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-17: 1Patch / Workaround · 2026-06-17: 1Technical Details · 2026-06-17: 106-17
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
Full discourse1 post
  • ThreatCluster@threatcluster
    Patch

    Fedora reported that Nextcloud Server 33.0.5 for Fedora 43/44 and EPEL fixes CVE-2026-45690, an authentication bypass allowing two-factor login circumvention, along with CVE-2026-45810 and CVE-2026-45285 data exposure flaws. https://threatcluster.io/cluster/critical-authentication-bypass-vulnerabilities-in-nextcloud--13d5065d

    Post summary

    Fedora has released updates for Nextcloud Server 33.0.5 that address CVE‑2026‑45690 – an authentication bypass – along with additional data exposure flaws CVE‑2026‑45810 and CVE‑2026‑45285, demonstrating the availability of patches for these vulnerabilities.

    0000054
    356 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appnextcloudnextcloud_server---
Appnextcloudnextcloud_server---

Explore more