A significant security flaw has been identified in the Nextcloud Tables application, tracked as CVE-2026-45722. This vulnerability allows an unauthorized user, provided they have access to the Tables app, to perform a limited form of SQL injection. While not a full-scale SQL injection, this flaw could potentially allow attackers to extract small pieces of information or cause delays in the database, posing a risk to data confidentiality and service availability.
CVE Details
- Product Name: Nextcloud Tables app
- Published Date: May 13, 2026
- Severity: High
- Status: Analyzed
Affected Products
The Nextcloud Tables app is affected across several versions. Specifically, users running versions from 0.9.0 up to, but not including, 0.9.7, and versions from 1.0.0 up to, but not including, 1.0.2 are vulnerable.
Current Status
This vulnerability has been analyzed and publicly disclosed. Details regarding its impact and recommended fixes are available, allowing users to take necessary steps to secure their Nextcloud instances.
Severity Level
Rated with a CVSS score of 7.1, this vulnerability is categorized as High severity. This rating indicates that while an attacker needs some privileges (low privileges) and no user interaction is required, the attack can be executed over the network (network attack vector) with low complexity. It primarily impacts confidentiality significantly, allowing for high information disclosure, and has a low impact on availability, potentially causing minor service interruptions.
Possible Solutions
Nextcloud has released patches to address this vulnerability. Users are strongly advised to update their Tables app to the following patched versions immediately:
- For the 0.x.x branch: Update to version 0.9.7 or later.
- For the 1.x.x branch: Update to version 1.0.2 or later.
If immediate patching is not possible, a temporary workaround is to disable the Nextcloud Tables app until the update can be applied.
References
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-5h2w-c7px-hp4j
https://github.com/nextcloud/tables/pull/2186
https://hackerone.com/reports/3446689


