CVE-2026-45156: Nextcloud: Authentication Bypass in ID4me handling via Missing JWT Signature Verification in User OIDC
Nextcloud is an open source content collaboration platform. From versions 0.3.0 to before 3.1.0, 5.0.0 to before 5.1.0, and 6.0.0 to before 6.4.0, a missing signature verification in User OIDC allowed a malicious ID4me authority to identify as any user. This issue has been patched in versions 3.1.0, 4.1.0, 5.1.0, 6.4.0 and 8.3.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.1.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.1.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.1.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.4.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.3.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45156?
CVE-2026-45156 has a high severity rating of 8.1.
Is CVE-2026-45156 exploitable?
Yes, CVE-2026-45156 is exploitable due to an authentication bypass vulnerability.
How do I fix CVE-2026-45156?
To fix CVE-2026-45156, upgrade to Nextcloud versions 3.1.0, 5.1.0, or 6.4.0 and later.
What are the affected versions for CVE-2026-45156?
CVE-2026-45156 affects Nextcloud versions from 0.3.0 to before 3.1.0, 5.0.0 to before 5.1.0, and 6.0.0 to before 6.4.0.
What type of attacks can CVE-2026-45156 facilitate?
CVE-2026-45156 can facilitate unauthorized access as it allows attackers to impersonate any user without proper verification.