Nextcloud Server Unauthorized Public Link Vulnerability (CVE-2026-45285) — Medium Severity

Nextcloud Server Unauthorized Public Link Vulnerability (CVE-2026-45285) — Medium Severity

In today’s interconnected digital world, collaboration platforms are essential. Nextcloud, a popular open-source solution, empowers users to share files and folders seamlessly. However, a recently discovered vulnerability could inadvertently expose your sensitive data if not addressed promptly.

This issue, identified as CVE-2026-45285, centers around how Nextcloud handles file and folder sharing with external members of a Nextcloud Team. When a user shares content with a team that includes individuals who don’t have a Nextcloud account (external members invited via email), the system automatically creates a hidden public link for them. What makes this concerning is that this link isn’t visible to the folder owner in the normal sharing interface, meaning they wouldn’t even know it exists.

The public link grants the external member the same permissions as the Team’s access, which could include the ability to read, write, delete, reshare, and download all data within that shared folder. If this hidden link falls into the wrong hands or is intercepted, an unauthorized individual could gain full access to the shared data without needing any further authentication.

CVE Details

  • Product: Nextcloud Server
  • Published Date: June 1, 2026
  • Severity: Medium
  • Status: Analyzed

Affected Products

The vulnerability impacts specific versions of Nextcloud Server:

  • Nextcloud Server versions from 32.0.0 up to, but not including, 32.0.9.
  • Nextcloud Server versions from 33.0.0 up to, but not including, 33.0.3.

Current Status

This vulnerability has been thoroughly analyzed, and Nextcloud has released patches to address the issue. This means that users have a clear path to secure their installations against this specific threat.

Severity Level

The CVE-2026-45285 has been assigned a “Medium” severity rating. While not critical, it poses a significant risk due to the potential for unauthorized data access and manipulation. The fact that the public link is hidden from the owner increases the risk, as administrators and users may not be aware of the exposure until it’s too late. Organizations using affected Nextcloud versions for sensitive data sharing should prioritize applying the available patches.

Possible Solutions

To protect your Nextcloud instance from this unauthorized public link vulnerability, it is crucial to update to the patched versions as soon as possible. Nextcloud has released fixes in the following updates:

  • Upgrade to Nextcloud Server version 32.0.9 or later.
  • Upgrade to Nextcloud Server version 33.0.3 or later.

Regularly updating your software is a fundamental cybersecurity practice. We strongly recommend all Nextcloud users review their current versions and implement these patches without delay. Additionally, review your sharing policies and external collaboration practices to ensure they align with your organization’s security requirements.

References

https://github.com/nextcloud/circles/pull/2454

https://github.com/nextcloud/security-advisories/security/advisories/GHSA-r3xh-x86g-hw4m

https://hackerone.com/reports/3625932

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.