
Fedora reported that Nextcloud Server 33.0.5 for Fedora 43/44 and EPEL fixes CVE-2026-45690, an authentication bypass allowing two-factor login circumvention, along with CVE-2026-45810 and CVE-2026-45285 data exposure flaws. https://threatcluster.io/cluster/critical-authentication-bypass-vulnerabilities-in-nextcloud--13d5065d
Post summary
Fedora has released updates for Nextcloud Server 33.0.5 that address CVE‑2026‑45690 – an authentication bypass – along with additional data exposure flaws CVE‑2026‑45810 and CVE‑2026‑45285, demonstrating the availability of patches for these vulnerabilities.
