Nextcloud Server Attachment Access Bypass Vulnerability (CVE-2026-45282) — Medium Severity

Understanding the Nextcloud Attachment Access Bypass

Nextcloud, a popular open-source platform for content collaboration, recently disclosed a vulnerability that could allow unauthorized access to shared file attachments. This issue, identified as CVE-2026-45282, primarily affects how Nextcloud handles attachments within link shares, potentially exposing sensitive information.

The vulnerability makes it possible for an authenticated user to bypass existing password protections and download restrictions on shared attachments. If an attacker knows the share token and a specific document ID for a file they own, they could gain access to attachments associated with directly shared files. While accessing attachments within shared folders is harder, requiring knowledge or a guess of a document ID for a file inside that folder, the core risk remains. It’s important to note that this vulnerability only grants access to attachments, not the main shared file or folder itself.

CVE Details

  • Product Name: Nextcloud Server, Nextcloud Enterprise Server
  • Published Date: June 1, 2026
  • Severity: Medium
  • Status: Analyzed

Affected Products

This vulnerability impacts various versions of Nextcloud Server and Nextcloud Enterprise Server:

Nextcloud Server:

  • Versions 32.0.0 through 32.0.8 (i.e., before 32.0.9)
  • Versions 33.0.0 through 33.0.2 (i.e., before 33.0.3)

Nextcloud Enterprise Server:

  • Versions 27.0.0 through 27.1.11.4 (i.e., before 27.1.11.5)
  • Versions 28.0.0 through 28.0.14.16 (i.e., before 28.0.14.17)
  • Versions 29.0.0 through 29.0.16.15 (i.e., before 29.0.16.16)
  • Versions 30.0.0 through 30.0.17.8 (i.e., before 30.0.17.9)
  • Versions 31.0.0 through 31.0.14.4 (i.e., before 31.0.14.5)
  • Versions 32.0.0 through 32.0.8 (i.e., before 32.0.9)
  • Versions 33.0.0 through 33.0.2 (i.e., before 33.0.3)

Current Status

The vulnerability has been officially analyzed and confirmed by Nextcloud. Information regarding the impact and available fixes has been publicly disclosed to help users secure their installations.

Severity Level

CVE-2026-45282 has a CVSS score of 6.5, classifying it as a Medium severity vulnerability. This score indicates that while an exploit requires an authenticated attacker and knowledge of a share token, successful exploitation could lead to high confidentiality impacts by exposing sensitive attachments.

Possible Solutions

Nextcloud has released patches to address this vulnerability. It is highly recommended that users update their installations immediately:

For Nextcloud Server:

  • Upgrade to version 33.0.3
  • Upgrade to version 32.0.9

For Nextcloud Enterprise Server:

  • Upgrade to version 33.0.3
  • Upgrade to version 32.0.9
  • Upgrade to version 31.0.14.5
  • Upgrade to version 30.0.17.9
  • Upgrade to version 29.0.16.16
  • Upgrade to version 28.0.14.17
  • Upgrade to version 27.1.11.5

Workaround:

If immediate patching is not possible, a temporary workaround is to disable the "Text" app within your Nextcloud instance. This might reduce functionality but mitigates the risk until a full update can be applied.

References

  • https://github.com/nextcloud/security-advisories/security/advisories/GHSA-35fx-69q6-xpjr
  • https://github.com/nextcloud/text/pull/8499
  • https://hackerone.com/reports/3577244
Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.