CVE-2026-45159: Nextcloud: Files drop share links for end-to-end encrypted folders allowed to drop files into other folders of the share owner
Nextcloud is an open source content collaboration platform. From versions 1.15.0 to before 1.15.4, 1.16.0 to before 1.16.3, 1.17.0 to before 1.17.1, and 1.18.0 to before 1.18.1, a malicious user with access to an end-to-end encrypted files drop link was able to also drop files into other end-to-end encrypted folders of the share owner. Reading and modifying of other files was not possible. This issue has been patched in versions 1.15.4, 1.16.3, 1.17.1, 1.18.1, and 2.0.0-rc.7.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.15.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.16.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.17.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.18.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.0-rc.7
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45159?
The severity of CVE-2026-45159 is rated as low with a score of 3.5.
How do I fix CVE-2026-45159?
To fix CVE-2026-45159, you should update Nextcloud to version 1.15.4 or later, 1.16.3 or later, 1.17.1 or later, or 1.18.1 or later.
What are the affected versions for CVE-2026-45159?
CVE-2026-45159 affects Nextcloud versions from 1.15.0 to before 1.15.4, 1.16.0 to before 1.16.3, 1.17.0 to before 1.17.1, and 1.18.0 to before 1.18.1.
What type of attack does CVE-2026-45159 involve?
CVE-2026-45159 involves a malicious user exploiting files drop share links to drop files into other folders of the share owner.
What impact does CVE-2026-45159 have on the affected systems?
The impact of CVE-2026-45159 is that it allows unauthorized file uploads into other end-to-end encrypted folders.