Nextcloud Server Unauthorized Public Link Vulnerability (CVE-2026-45285) — Medium Severity
In today’s interconnected digital world, collaboration platforms are essential. Nextcloud, a popular open-source solution, empowers users to share files and folders seamlessly. However, a recently discovered vulnerability could inadvertently expose your sensitive data if not addressed promptly.
This issue, identified as CVE-2026-45285, centers around how Nextcloud handles file and folder sharing with external members of a Nextcloud Team. When a user shares content with a team that includes individuals who don’t have a Nextcloud account (external members invited via email), the system automatically creates a hidden public link for them. What makes this concerning is that this link isn’t visible to the folder owner in the normal sharing interface, meaning they wouldn’t even know it exists.
The public link grants the external member the same permissions as the Team’s access, which could include the ability to read, write, delete, reshare, and download all data within that shared folder. If this hidden link falls into the wrong hands or is intercepted, an unauthorized individual could gain full access to the shared data without needing any further authentication.
CVE Details
- Product: Nextcloud Server
- Published Date: June 1, 2026
- Severity: Medium
- Status: Analyzed
Affected Products
The vulnerability impacts specific versions of Nextcloud Server:
- Nextcloud Server versions from 32.0.0 up to, but not including, 32.0.9.
- Nextcloud Server versions from 33.0.0 up to, but not including, 33.0.3.
Current Status
This vulnerability has been thoroughly analyzed, and Nextcloud has released patches to address the issue. This means that users have a clear path to secure their installations against this specific threat.
Severity Level
The CVE-2026-45285 has been assigned a “Medium” severity rating. While not critical, it poses a significant risk due to the potential for unauthorized data access and manipulation. The fact that the public link is hidden from the owner increases the risk, as administrators and users may not be aware of the exposure until it’s too late. Organizations using affected Nextcloud versions for sensitive data sharing should prioritize applying the available patches.
Possible Solutions
To protect your Nextcloud instance from this unauthorized public link vulnerability, it is crucial to update to the patched versions as soon as possible. Nextcloud has released fixes in the following updates:
- Upgrade to Nextcloud Server version 32.0.9 or later.
- Upgrade to Nextcloud Server version 33.0.3 or later.
Regularly updating your software is a fundamental cybersecurity practice. We strongly recommend all Nextcloud users review their current versions and implement these patches without delay. Additionally, review your sharing policies and external collaboration practices to ensure they align with your organization’s security requirements.
References
https://github.com/nextcloud/circles/pull/2454
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-r3xh-x86g-hw4m
https://hackerone.com/reports/3625932


