CVE-2026-45267: Nextcloud: Missing permission check for from submissions
Nextcloud is an open source content collaboration platform. Prior to version 5.2.6, a missing permissions check allowed users to request reading form submissions of other users. This issue has been patched in version 5.2.6.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Nextcloudto a version that resolves this vulnerability.Fixed in 5.2.6
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45267?
The severity of CVE-2026-45267 is rated medium with a CVSS score of 6.5.
How do I fix CVE-2026-45267?
To fix CVE-2026-45267, upgrade to Nextcloud version 5.2.6 or later.
What issue does CVE-2026-45267 address?
CVE-2026-45267 addresses a missing permission check that allows unauthorized reading of form submissions by users.
Which versions of Nextcloud are affected by CVE-2026-45267?
CVE-2026-45267 affects all versions of Nextcloud prior to 5.2.6.
What is the impact of CVE-2026-45267?
The impact of CVE-2026-45267 is that it can lead to information leakage, allowing unauthorized access to sensitive user submissions.