An important security flaw has been found in the Nextcloud Tables app. This issue allows a logged-in user to run harmful commands on the database. This means they could potentially steal sensitive information or change important data within your Nextcloud setup. While the initial limit for these commands is small, a clever attacker can get around this, making the vulnerability more serious.
CVE Details
- Product Name: Nextcloud Tables App
- Published Date: June 1, 2026
- Severity: High
- Status: Analyzed
Affected Products
The following versions of the Nextcloud Tables App are affected:
- Versions 0.7.0 to before 0.7.7
- Versions 0.8.0 to before 0.8.10
- Versions 0.9.0 to before 0.9.8
- Versions 1.0.0 to before 1.0.4
Current Status
This vulnerability has been thoroughly analyzed, and patches are readily available to address the issue.
Severity Level
This vulnerability has been assigned a High severity rating, with a CVSS score of 8.2. A high severity rating indicates that exploiting this flaw could lead to significant unauthorized access or data manipulation, posing a considerable risk to the integrity and confidentiality of your data within the affected system.
Possible Solutions
To protect your Nextcloud installation from this SQL Injection vulnerability, it is crucial to update the Tables app immediately. The following patched versions address this security flaw:
- Nextcloud Tables App 0.7.7
- Nextcloud Tables App 0.8.10
- Nextcloud Tables App 0.9.8
- Nextcloud Tables App 1.0.4
- Nextcloud Tables App 2.0.0 (or newer)
If immediate patching is not feasible, a temporary workaround involves disabling the Nextcloud Tables app. However, updating to a patched version is the strongly recommended long-term solution to ensure your system’s security.
References
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-x43f-gmgh-vvjj
- https://github.com/nextcloud/tables/pull/2309
- https://hackerone.com/reports/3462991


