Improper access control in Nextcloud Server and Nextcloud Enterprise Server - CVE-2026-61527
Published: August 10, 2026
Vulnerability identifier: #VU141394
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-61527
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the logic issue broke the permissions restrictions on link shares. A remote user can bypass implemented security restrictions and gain full write permissions to the contents of the share.
Affected software
Nextcloud Server
Nextcloud Enterprise Server
Nextcloud Enterprise Server
How to mitigate CVE-2026-61527
Install updates from vendor's website.
Nextcloud Server - addressed in versions 32.0.12, 33.0.6, 34.0.1
Nextcloud Enterprise Server - addressed in versions 32.0.12, 33.0.6
Nextcloud Enterprise Server - addressed in versions 32.0.12, 33.0.6