CVE-2026-45153
Received Received - Intake
PIN Bypass via Back-Button in Nextcloud Files Android App

Publication date: 2026-06-01

Last updated on: 2026-06-01

Assigner: GitHub, Inc.

Description
Nextcloud is an open source content collaboration platform. From version 33.0.0 to before version 33.1.0, after unlocking a locked Android phone the back-button could be used to bypass the Nextcloud Files app PIN. This issue has been patched in version 33.1.0.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-01
Last Modified
2026-06-01
Generated
2026-06-01
AI Q&A
2026-06-01
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
nextcloud android to 33.1.0 (exc)
nextcloud android 33.1.0
nextcloud nextcloud to 33.1.0 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Attack-Flow Graph
AI Powered Q&A
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:

The vulnerability allows an attacker to bypass the Nextcloud Files app PIN after unlocking a locked Android phone, potentially leading to unauthorized access to confidential data stored within the app.

Such unauthorized data access could impact compliance with data protection regulations like GDPR and HIPAA, which require safeguarding personal and sensitive information against unauthorized access.

However, the provided information does not explicitly discuss the direct effects on compliance with these standards or any regulatory implications.


Can you explain this vulnerability to me?

CVE-2026-45153 is a vulnerability in the Nextcloud Android Files app that allows an attacker to bypass the app's PIN protection by using the back button after unlocking a locked Android phone.

This issue affects versions 33.0.0 up to but not including 33.1.0 and has been fixed in version 33.1.0.

The vulnerability is classified as CWE-287 (Improper Authentication) and has a CVSS score of 4.6, indicating a moderate severity.


How can this vulnerability impact me? :

This vulnerability can impact you by allowing unauthorized access to confidential data stored in the Nextcloud Files app.

An attacker with physical access to a locked Android phone could exploit the back button to bypass the app's PIN and gain access to sensitive information.

The primary impact is on confidentiality, potentially exposing private data without proper authentication.


How can this vulnerability be detected on my network or system? Can you suggest some commands?

There is no specific information provided about detecting this vulnerability on a network or system, nor are there any suggested commands for detection.


What immediate steps should I take to mitigate this vulnerability?

To mitigate this vulnerability, users should upgrade the Nextcloud Android Files app to version 33.1.0 or later, where the PIN bypass issue has been patched.

No workarounds are available, so applying the official update is the recommended immediate step.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart