Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 03 Jun 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:nextcloud:approval:*:*:*:*:*:nextcloud:*:* |
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nextcloud
Nextcloud approval |
|
| Vendors & Products |
Nextcloud
Nextcloud approval |
Mon, 01 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 01 Jun 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, a privilege escalation vulnerability exists in the Approval app that allows a user without sharing permissions to force the system to share a file with approvers. This results in an authorization bypass and privilege escalation, allowing unauthorized distribution of restricted files. This issue has been patched in version 2.7.2. | |
| Title | Nextcloud: Authorization bypass in approval feature allows unauthorized file sharing with approvers | |
| Weaknesses | CWE-285 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-01T19:31:53.967Z
Reserved: 2026-05-11T18:41:13.157Z
Link: CVE-2026-45275
Updated: 2026-06-01T19:31:49.154Z
Status : Analyzed
Published: 2026-06-01T19:16:49.517
Modified: 2026-06-03T17:39:44.920
Link: CVE-2026-45275
No data.
OpenCVE Enrichment
Updated: 2026-06-02T20:53:58Z