Nextcloud Tables Information Disclosure Vulnerability (CVE-2026-45544) — Medium Severity

Overview

Nextcloud Tables, an open-source platform for collaborative data management, has been identified with an information disclosure vulnerability. This security flaw could allow users with read-only access to inadvertently view sensitive filter criteria within the application. This means that private information used to sort or restrict data views, which should remain confidential, could become visible to unauthorized individuals. This issue affects specific older versions of the Nextcloud Tables app and has since been addressed by the developers.

CVE Details

  • Product Name: Nextcloud Tables
  • CVE ID: CVE-2026-45544
  • Published Date: June 1, 2026
  • Severity: Medium
  • Status: Analyzed

Affected Products

The vulnerability primarily impacts installations running the Nextcloud Tables app. Specifically, affected versions range from 0.8.0 up to, but not including, version 1.0.4. This means if you are currently using Nextcloud Tables versions 0.8.0, 0.9.0, 1.0.0, 1.0.1, 1.0.2, or 1.0.3, your system is vulnerable. It is crucial for administrators and users to identify their current version and take appropriate action to mitigate this risk.

Current Status

The vulnerability, identified as CVE-2026-45544, has been thoroughly analyzed and publicly disclosed. Fortunately, Nextcloud has already released patches to remediate this issue. The status is “Analyzed,” indicating that the vulnerability has been understood and a solution is available. This allows users to proactively secure their systems.

Severity Level

This information disclosure vulnerability is rated as Medium severity, with a CVSS (Common Vulnerability Scoring System) score of 4.3. The CVSS score reflects that while exploiting this vulnerability requires low privileges, it does not necessitate any user interaction from the victim. The primary impact is on confidentiality, meaning sensitive information could be exposed. There is no direct impact on the integrity or availability of the system. While not critical, the exposure of filter criteria could still reveal underlying data structures or business logic that should remain private.

Possible Solutions

To safeguard your Nextcloud Tables installation against this vulnerability, immediate action is recommended:

  • Upgrade Immediately: The most effective solution is to upgrade your Nextcloud Tables app to a patched version. Nextcloud has released fixes in versions 1.0.4 and 2.0.0. Ensure you update to one of these versions or any newer release.
  • Temporary Workaround: If an immediate upgrade is not feasible, a temporary mitigation involves disabling the Nextcloud Tables app. This will prevent the exposure of view filter criteria, but it will also mean the application is unusable until an upgrade can be performed.

Regularly checking for and applying security updates is a best practice for maintaining the security of your Nextcloud environment.

References

https://github.com/nextcloud/security-advisories/security/advisories/GHSA-vvxm-6jjp-m9mp
https://github.com/nextcloud/tables/pull/2312
https://hackerone.com/reports/3483753

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.