
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-45285 is an authorization bypass vulnerability in Nextcloud Server that causes hidden public links to be automatically created when a folder or file is shared with a Nextcloud Team containing an external member (a person added via email without a Nextcloud account). These links are invisible to the folder owner in the sharing interface but are emailed to the external member, granting full read, write, delete, reshare, and download permissions without authentication. The vulnerability affects Nextcloud Server (community and enterprise editions) versions 32.0.0 through 32.0.8 and 33.0.0 through 33.0.2. It was published on June 1, 2026, and carries a CVSS v3.1 base score of 6.4 (Medium) (GitHub Advisory, Red Hat Bugzilla).
The root cause is classified as CWE-862 (Missing Authorization) and CWE-639 (Authorization Bypass Through User-Controlled Key), residing in the Nextcloud Circles (Teams) application's share-handling logic. When a Team share is created for a group that includes an external (email-only) member, the system generates a public link token and emails it to the external member without registering the link in the folder's visible share list, bypassing normal access control checks. The fix was implemented in the nextcloud/circles app via a pull request that updated share handling to prevent public link token generation for internal circle/team shares involving external members (GitHub PR, GitHub Advisory). Exploitation requires that an attacker either be the external member who received the email or intercept the emailed link.
An attacker who obtains or intercepts the auto-generated public link can read, modify, delete, reshare, and download all files within the shared folder without any authentication. The folder owner has no visibility into the link's existence through the normal sharing interface and cannot revoke it via standard controls, leaving the data exposure persistent until the system is patched. Confidentiality and integrity impacts are both rated High, though availability is unaffected (GitHub Advisory, Red Hat Bugzilla).
/s/<token>) from unexpected IP addresses or at unusual times, particularly for shares not visible in the sharing UI./index.php/s/<token> or /s/<token> originating from external or unknown IP addresses against folders shared with Teams.Nextcloud has released patched versions 32.0.9 and 33.0.3 for both community and enterprise editions, and upgrading is the only recommended remediation as no workaround is available (GitHub Advisory). Administrators should also audit existing Team shares that include external members and review public links for any unauthorized access. Until patching is possible, consider disabling Team shares with external members or restricting the Circles app's ability to add external (email-only) members.
The advisory was published by Nextcloud's security team (DorraJaouad) on May 12, 2026, and the fix was merged into the Circles app on April 23, 2026, prior to public disclosure (GitHub PR, GitHub Advisory). Red Hat tracked the issue via Bugzilla and rated it medium severity (Red Hat Bugzilla). No significant broader media coverage or notable researcher commentary beyond standard vulnerability tracking has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."