CVE-2026-45154: Nextcloud: Improper Access Control in Collectives
Nextcloud is an open source content collaboration platform. From version 2.6.0 to before version 4.3.0, when a previous collective pages was deleted and the collective was shared view-only, guests with access to the collective were able to access the deleted pages directly from the trashbin. This issue has been patched in version 4.3.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Nextcloudto a version that resolves this vulnerability.Fixed in 4.3.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45154?
The severity of CVE-2026-45154 is classified as low, with a score of 2.6.
How do I fix CVE-2026-45154?
To fix CVE-2026-45154, upgrade your Nextcloud instance to version 4.3.0 or later.
What does CVE-2026-45154 affect?
CVE-2026-45154 affects Nextcloud versions 2.6.0 through before 4.3.0.
What is the impact of CVE-2026-45154?
The impact of CVE-2026-45154 allows guests with view-only access to access deleted pages directly from the trashbin.
What type of vulnerability is CVE-2026-45154?
CVE-2026-45154 is categorized as an improper access control vulnerability.