CVE-2026-45155: Nextcloud: Private circle can be added to another circle via API
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.7 and 33.0.0 to before 33.0.1, a missing access check on API level allowed to add unknown circles by their ID directly to other circles. Since circle IDs have 62^15 complexity by default this is still unlikely to be executable at will, but if access to an ID was available via another source, memberships could be tracked like this. It is recommended that the Nextcloud Server is upgraded to 32.0.7 or 33.0.1. It is recommended that the Nextcloud Enterprise Server is upgraded to 29.0.16.14, 30.0.17.8, 31.0.14.3, 32.0.7 or 33.0.1
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Nextcloud Serverto a version that resolves this vulnerability.Fixed in 32.0.7 - Upgrade
Upgrade
Nextcloud Serverto a version that resolves this vulnerability.Fixed in 33.0.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45155?
The severity of CVE-2026-45155 is classified as low with a score of 2.6.
How do I fix CVE-2026-45155?
To fix CVE-2026-45155, you should update Nextcloud Server to version 32.0.7 or 33.0.1 or later.
What systems are affected by CVE-2026-45155?
CVE-2026-45155 affects Nextcloud Server versions 32.0.0 to before 32.0.7 and 33.0.0 to before 33.0.1.
What does CVE-2026-45155 vulnerability allow an attacker to do?
CVE-2026-45155 allows an attacker to add unknown circles by their ID directly to other circles due to a missing access check.
What is the risk level of exploiting CVE-2026-45155?
The risk level of exploiting CVE-2026-45155 is considered low due to the complexity of circle IDs.