CVE-2026-45266: Nextcloud: Unauthorized force-mute from missing permission check when using internal signaling
Nextcloud is an open source content collaboration platform. Prior to versions 21.1.10, 22.0.11, and 23.0.3, a low-privileged user can force other user's microphones to be muted in calls when no High-performance Backend is installed. This issue has been patched in versions 21.1.10, 22.0.11, and 23.0.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
nextcloudto a version that resolves this vulnerability.Fixed in 21.1.10 - Upgrade
Upgrade
nextcloudto a version that resolves this vulnerability.Fixed in 22.0.11 - Upgrade
Upgrade
nextcloudto a version that resolves this vulnerability.Fixed in 23.0.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45266?
The severity of CVE-2026-45266 is classified as low with a score of 3.5.
How do I fix CVE-2026-45266?
To fix CVE-2026-45266, update Nextcloud to versions 21.1.10, 22.0.11, or 23.0.3 or newer.
What does CVE-2026-45266 affect?
CVE-2026-45266 affects the Nextcloud content collaboration platform where low-privileged users can mute others' microphones in calls.
What is the impact of CVE-2026-45266?
The impact of CVE-2026-45266 allows unauthorized users to disrupt ongoing calls by force-muting other users' microphones.
Is there a workaround for CVE-2026-45266?
No specific workaround is provided for CVE-2026-45266; upgrading to the patched versions is recommended.