CVE-2026-45277: Nextcloud: Information disclosure in Nextcloud Approval app via fileId parameter reveals workflow associations
Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, authenticated users can check if arbitrary files are associated with specific approval workflows where they can request approval. This issue has been patched in version 2.7.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
nextcloud/approval appto a version that resolves this vulnerability.Fixed in 2.7.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45277?
The severity of CVE-2026-45277 is classified as low with a score of 3.3.
How do I fix CVE-2026-45277?
To fix CVE-2026-45277, upgrade to Nextcloud Approval app version 2.7.2 or later.
What is the risk associated with CVE-2026-45277?
CVE-2026-45277 has a risk score of 18, indicating an information disclosure vulnerability in Nextcloud.
What is the nature of the vulnerability described in CVE-2026-45277?
CVE-2026-45277 allows authenticated users to disclose information about approval workflows associated with arbitrary files via the fileId parameter.
Is there a patch available for CVE-2026-45277?
Yes, a patch is available in Nextcloud Approval app version 2.7.2 to address CVE-2026-45277.