CVE-2026-45153
PIN Bypass via Back-Button in Nextcloud Files Android App
Publication date: 2026-06-01
Last updated on: 2026-06-01
Assigner: GitHub, Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| nextcloud | android | to 33.1.0 (exc) |
| nextcloud | android | 33.1.0 |
| nextcloud | nextcloud | to 33.1.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-287 | When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct. |
Attack-Flow Graph
AI Powered Q&A
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
The vulnerability allows an attacker to bypass the Nextcloud Files app PIN after unlocking a locked Android phone, potentially leading to unauthorized access to confidential data stored within the app.
Such unauthorized data access could impact compliance with data protection regulations like GDPR and HIPAA, which require safeguarding personal and sensitive information against unauthorized access.
However, the provided information does not explicitly discuss the direct effects on compliance with these standards or any regulatory implications.
Can you explain this vulnerability to me?
CVE-2026-45153 is a vulnerability in the Nextcloud Android Files app that allows an attacker to bypass the app's PIN protection by using the back button after unlocking a locked Android phone.
This issue affects versions 33.0.0 up to but not including 33.1.0 and has been fixed in version 33.1.0.
The vulnerability is classified as CWE-287 (Improper Authentication) and has a CVSS score of 4.6, indicating a moderate severity.
How can this vulnerability impact me? :
This vulnerability can impact you by allowing unauthorized access to confidential data stored in the Nextcloud Files app.
An attacker with physical access to a locked Android phone could exploit the back button to bypass the app's PIN and gain access to sensitive information.
The primary impact is on confidentiality, potentially exposing private data without proper authentication.
How can this vulnerability be detected on my network or system? Can you suggest some commands?
There is no specific information provided about detecting this vulnerability on a network or system, nor are there any suggested commands for detection.
What immediate steps should I take to mitigate this vulnerability?
To mitigate this vulnerability, users should upgrade the Nextcloud Android Files app to version 33.1.0 or later, where the PIN bypass issue has been patched.
No workarounds are available, so applying the official update is the recommended immediate step.