CVE-2026-45264
Deferred
Deferred - Pending Action
Privilege Escalation in Nextcloud Team Folder
Publication date: 2026-06-01
Last updated on: 2026-06-01
Assigner: GitHub, Inc.
Description
Description
Nextcloud is an open source content collaboration platform. From versions 17.0.0 to before 17.0.15, 18.0.0 to before 18.1.12, 19.0.0 to before 19.1.16, 20.0.0 to before 20.1.11, and 21.0.0 to before 21.0.4, a user with READ and CREATE permission, but no UPDATE permission for a team folder can rename files in the team folder. This issue has been patched in versions 17.0.15, 18.1.12, 19.1.16, 20.1.11, and 21.0.4.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| nextcloud | team_folders | From 17.0.0 (inc) to 17.0.15 (exc) |
| nextcloud | team_folders | From 18.0.0 (inc) to 18.1.12 (exc) |
| nextcloud | team_folders | From 19.0.0 (inc) to 19.1.16 (exc) |
| nextcloud | team_folders | From 20.0.0 (inc) to 20.1.11 (exc) |
| nextcloud | team_folders | From 21.0.0 (inc) to 21.0.4 (exc) |
| nextcloud | team_folders | 17.0.15 |
| nextcloud | team_folders | 18.1.12 |
| nextcloud | team_folders | 19.1.16 |
| nextcloud | team_folders | 20.1.11 |
| nextcloud | team_folders | 21.0.4 |
| nextcloud | nextcloud | From 17.0.0 (inc) to 17.0.15 (exc) |
| nextcloud | nextcloud | From 18.0.0 (inc) to 18.1.12 (exc) |
| nextcloud | nextcloud | From 19.0.0 (inc) to 19.1.16 (exc) |
| nextcloud | nextcloud | From 20.0.0 (inc) to 20.1.11 (exc) |
| nextcloud | nextcloud | From 21.0.0 (inc) to 21.0.4 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-284 | The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |