Nextcloud Tables SQL Injection Vulnerability (CVE-2026-45722) — High Severity

A significant security flaw has been identified in the Nextcloud Tables application, tracked as CVE-2026-45722. This vulnerability allows an unauthorized user, provided they have access to the Tables app, to perform a limited form of SQL injection. While not a full-scale SQL injection, this flaw could potentially allow attackers to extract small pieces of information or cause delays in the database, posing a risk to data confidentiality and service availability.

CVE Details

  • Product Name: Nextcloud Tables app
  • Published Date: May 13, 2026
  • Severity: High
  • Status: Analyzed

Affected Products

The Nextcloud Tables app is affected across several versions. Specifically, users running versions from 0.9.0 up to, but not including, 0.9.7, and versions from 1.0.0 up to, but not including, 1.0.2 are vulnerable.

Current Status

This vulnerability has been analyzed and publicly disclosed. Details regarding its impact and recommended fixes are available, allowing users to take necessary steps to secure their Nextcloud instances.

Severity Level

Rated with a CVSS score of 7.1, this vulnerability is categorized as High severity. This rating indicates that while an attacker needs some privileges (low privileges) and no user interaction is required, the attack can be executed over the network (network attack vector) with low complexity. It primarily impacts confidentiality significantly, allowing for high information disclosure, and has a low impact on availability, potentially causing minor service interruptions.

Possible Solutions

Nextcloud has released patches to address this vulnerability. Users are strongly advised to update their Tables app to the following patched versions immediately:

  • For the 0.x.x branch: Update to version 0.9.7 or later.
  • For the 1.x.x branch: Update to version 1.0.2 or later.

If immediate patching is not possible, a temporary workaround is to disable the Nextcloud Tables app until the update can be applied.

References

https://github.com/nextcloud/security-advisories/security/advisories/GHSA-5h2w-c7px-hp4j

https://github.com/nextcloud/tables/pull/2186

https://hackerone.com/reports/3446689

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.