Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, a privilege escalation vulnerability exists in the Approval app that allows a user without sharing permissions to force the system to share a file with approvers. This results in an authorization bypass and privilege escalation, allowing unauthorized distribution of restricted files. This issue has been patched in version 2.7.2.
Metrics
Affected Vendors & Products
References
History
Wed, 03 Jun 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:nextcloud:approval:*:*:*:*:*:nextcloud:*:* |
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nextcloud
Nextcloud approval |
|
| Vendors & Products |
Nextcloud
Nextcloud approval |
Mon, 01 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 01 Jun 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, a privilege escalation vulnerability exists in the Approval app that allows a user without sharing permissions to force the system to share a file with approvers. This results in an authorization bypass and privilege escalation, allowing unauthorized distribution of restricted files. This issue has been patched in version 2.7.2. | |
| Title | Nextcloud: Authorization bypass in approval feature allows unauthorized file sharing with approvers | |
| Weaknesses | CWE-285 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-06-01T16:51:22.429Z
Updated: 2026-06-01T19:31:53.967Z
Reserved: 2026-05-11T18:41:13.157Z
Link: CVE-2026-45275
Updated: 2026-06-01T19:31:49.154Z
Status : Analyzed
Published: 2026-06-01T19:16:49.517
Modified: 2026-06-03T17:39:44.920
Link: CVE-2026-45275
No data.