Nextcloud Forms Unauthorized Read Access Vulnerability (CVE-2026-45543) — Medium Severity

A Critical Flaw in Nextcloud Forms: What You Need to Know

Nextcloud Forms, an open-source platform for creating surveys and forms, has been found to have a security vulnerability, identified as CVE-2026-45543. This flaw could allow unauthorized individuals to access sensitive files that were uploaded by respondents. For IT administrators, developers, and even regular users, understanding this vulnerability is key to protecting data and ensuring the privacy of form submissions. This issue highlights the importance of keeping your software up-to-date and understanding who has access to your data, even after changes are made to user permissions.

CVE Details

This vulnerability affects Nextcloud Forms, a crucial component of the Nextcloud ecosystem. Here’s a quick overview of its specifics:

  • Product: Nextcloud Forms
  • Published Date: June 1, 2026
  • Severity: Medium
  • Status: Analyzed

The core of the problem lies in how Nextcloud Forms handles file sharing after a collaborator is removed. Specifically, if a user was previously given access to view form results, including uploaded files from respondents, they would retain unauthorized read access to those files even after their collaboration privileges were revoked. This means sensitive information could remain accessible to former team members, posing a significant risk to data confidentiality.

Affected Products

The unauthorized read access vulnerability impacts a specific range of Nextcloud Forms versions:

  • Nextcloud Forms versions: From 4.3.0 up to, but not including, version 5.2.7.

Users operating within this version range are strongly advised to review their installations and take appropriate action to mitigate the risk.

Current Status

As of June 4, 2026, this vulnerability has been thoroughly analyzed by the Nextcloud security team. A patch has been developed and integrated into the main development branch of Nextcloud Forms. However, it’s important to note that while the fix is available, successfully applying it to all affected older versions might require manual intervention, as some backport processes can fail and necessitate manual application of the patch.

Severity Level

The CVE-2026-45543 vulnerability has been assigned a Medium severity rating, with a CVSS Score of 5.3. This rating indicates that while the vulnerability is not critical, it is still a significant concern. Unauthorized read access to uploaded respondent files can lead to data breaches, exposure of personal information, and potential compliance issues. For any organization handling sensitive data via Nextcloud Forms, addressing this medium-severity flaw is essential to maintaining trust and security.

Possible Solutions

The most direct and effective solution is to update your Nextcloud Forms installation immediately. The developers have addressed this issue in version 5.2.7. Therefore, all users running affected versions (4.3.0 to before 5.2.7) should upgrade to version 5.2.7 or any subsequent stable release.

If you are on an older, unsupported branch of Nextcloud Forms, and an official patch for your specific version is not provided, you may need to perform a manual backport of the fix. It is always recommended to consult the official Nextcloud documentation or seek professional assistance for such complex updates to ensure data integrity and system stability.

It’s also a good practice to regularly review and audit user permissions, especially for collaborators who have handled sensitive data, and to ensure that data retention policies are strictly followed.

References

https://github.com/nextcloud/forms/pull/3291
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-q4fw-6jf8-5vhh
https://hackerone.com/reports/3617352

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.