CVE-2024-46958
Nextcloud Desktop Client vulnerability analysis and mitigation

Overview

In Nextcloud Desktop Client versions 3.13.1 through 3.13.3 on Linux systems, a security vulnerability was identified where synchronized files between the server and client could have their permissions incorrectly modified, becoming world writable or world readable. This vulnerability was discovered in June 2024 and was fixed in version 3.13.4 (NVD, Debian Tracker).

Technical details

The vulnerability affects the file permission handling mechanism in the Nextcloud Desktop Client. When synchronizing files or creating new folders, the client incorrectly sets folder permissions to allow write access for group and others, instead of limiting it to the owner. The issue has been assigned a CVSS v3.1 base score of 9.1 (Critical) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N, indicating high severity with potential for unauthorized access and modification of files (NVD).

Impact

The vulnerability could allow unauthorized users to read or modify synchronized files, potentially compromising data confidentiality and integrity. Any folder synchronized between the Nextcloud server and client could become accessible to other users on the same system, exposing sensitive information or allowing unauthorized modifications (Github Issue).

Mitigation and workarounds

Users are advised to upgrade to Nextcloud Desktop Client version 3.13.4, which contains the fix for this vulnerability. The fix involves narrowing down the ReadWrite folder permissions to owner-only access, preventing unauthorized access by other users on the system (Github PR).

Additional resources


SourceThis report was generated using AI

Related Nextcloud Desktop Client vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-46958CRITICAL9.1
  • Nextcloud Desktop ClientNextcloud Desktop Client
  • cpe:2.3:a:nextcloud:desktop
NoYesSep 16, 2024
CVE-2024-37885HIGH7.8
  • Nextcloud Desktop ClientNextcloud Desktop Client
  • cpe:2.3:a:nextcloud:desktop
NoYesJun 14, 2024
CVE-2024-52510HIGH7.5
  • Nextcloud Desktop ClientNextcloud Desktop Client
  • cpe:2.3:a:nextcloud:desktop
NoYesNov 15, 2024
CVE-2025-47792MEDIUM6.1
  • Nextcloud Desktop ClientNextcloud Desktop Client
  • nextcloud-desktop
NoYesMay 16, 2025
CVE-2025-66549LOW2.7
  • Nextcloud Desktop ClientNextcloud Desktop Client
  • cpe:2.3:a:nextcloud:desktop
NoYesDec 05, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management