Beveiligingsadvies

CVE-2026-45156

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-06-01 16:38:46
Laatst bijgewerkt 2026-06-03 03:55:47
Toegewezen door GitHub_M
CVSS-score 8.1
Status PUBLISHED

Beschrijving

Nextcloud is an open source content collaboration platform. From versions 0.3.0 to before 3.1.0, 5.0.0 to before 5.1.0, and 6.0.0 to before 6.4.0, a missing signature verification in User OIDC allowed a malicious ID4me authority to identify as any user. This issue has been patched in versions 3.1.0, 4.1.0, 5.1.0, 6.4.0 and 8.3.0.