CVE-2026-45285
Linux Fedora vulnerability analysis and mitigation

Overview

CVE-2026-45285 is an authorization bypass vulnerability in Nextcloud Server that causes hidden public links to be automatically created when a folder or file is shared with a Nextcloud Team containing an external member (a person added via email without a Nextcloud account). These links are invisible to the folder owner in the sharing interface but are emailed to the external member, granting full read, write, delete, reshare, and download permissions without authentication. The vulnerability affects Nextcloud Server (community and enterprise editions) versions 32.0.0 through 32.0.8 and 33.0.0 through 33.0.2. It was published on June 1, 2026, and carries a CVSS v3.1 base score of 6.4 (Medium) (GitHub Advisory, Red Hat Bugzilla).

Technical details

The root cause is classified as CWE-862 (Missing Authorization) and CWE-639 (Authorization Bypass Through User-Controlled Key), residing in the Nextcloud Circles (Teams) application's share-handling logic. When a Team share is created for a group that includes an external (email-only) member, the system generates a public link token and emails it to the external member without registering the link in the folder's visible share list, bypassing normal access control checks. The fix was implemented in the nextcloud/circles app via a pull request that updated share handling to prevent public link token generation for internal circle/team shares involving external members (GitHub PR, GitHub Advisory). Exploitation requires that an attacker either be the external member who received the email or intercept the emailed link.

Impact

An attacker who obtains or intercepts the auto-generated public link can read, modify, delete, reshare, and download all files within the shared folder without any authentication. The folder owner has no visibility into the link's existence through the normal sharing interface and cannot revoke it via standard controls, leaving the data exposure persistent until the system is patched. Confidentiality and integrity impacts are both rated High, though availability is unaffected (GitHub Advisory, Red Hat Bugzilla).

Exploitation steps

  1. Identify a target: Determine that a Nextcloud instance is running a vulnerable version (32.0.0–32.0.8 or 33.0.0–33.0.2) and that Teams (Circles) with external email members are in use.
  2. Obtain the public link: Either be the external member who receives the auto-generated link via email, or intercept the email in transit (e.g., via a compromised email account or man-in-the-middle attack on unencrypted email delivery).
  3. Access the shared folder: Open the public link in a browser — no Nextcloud account or credentials are required. The link grants the same permissions as the Team's configured access level.
  4. Perform unauthorized actions: Use the link to read, download, modify, delete, or reshare all files within the shared folder, as the link carries full Team permissions without further authentication checks (GitHub Advisory).

Indicators of compromise

  • Logs: Nextcloud server logs showing access to public share endpoints (/s/<token>) from unexpected IP addresses or at unusual times, particularly for shares not visible in the sharing UI.
  • Network: HTTP GET/POST requests to /index.php/s/<token> or /s/<token> originating from external or unknown IP addresses against folders shared with Teams.
  • File System: Unexpected modifications, deletions, or new files appearing in folders shared with Teams that include external members, without corresponding authenticated user activity in audit logs.
  • Email: Outbound emails from the Nextcloud instance to external addresses containing public share links for Team-shared folders — these can be identified in mail server logs as auto-generated notifications from the Circles app.

Mitigation and workarounds

Nextcloud has released patched versions 32.0.9 and 33.0.3 for both community and enterprise editions, and upgrading is the only recommended remediation as no workaround is available (GitHub Advisory). Administrators should also audit existing Team shares that include external members and review public links for any unauthorized access. Until patching is possible, consider disabling Team shares with external members or restricting the Circles app's ability to add external (email-only) members.

Community reactions

The advisory was published by Nextcloud's security team (DorraJaouad) on May 12, 2026, and the fix was merged into the Circles app on April 23, 2026, prior to public disclosure (GitHub PR, GitHub Advisory). Red Hat tracked the issue via Bugzilla and rated it medium severity (Red Hat Bugzilla). No significant broader media coverage or notable researcher commentary beyond standard vulnerability tracking has been observed.

Additional resources


SourceThis report was generated using AI

Related Linux Fedora vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55626HIGH8
  • xrdp logoxrdp
  • xrdp
NoYesJul 20, 2026
CVE-2026-54538HIGH7.5
  • xrdp logoxrdp
  • xrdp-selinux
NoYesJul 20, 2026
CVE-2026-55645MEDIUM6.5
  • xrdp logoxrdp
  • cpe:2.3:a:neutrinolabs:xrdp
NoYesJul 20, 2026
CVE-2026-55639MEDIUM5.3
  • xrdp logoxrdp
  • xrdp-selinux
NoYesJul 20, 2026
CVE-2026-55238MEDIUM5.3
  • xrdp logoxrdp
  • xrdp-selinux
NoYesJul 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management