Vulnerability Description
Nextcloud is an open source content collaboration platform. From version 33.0.0 to before version 33.1.0, after unlocking a locked Android phone the back-button could be used to bypass the Nextcloud Files app PIN. This issue has been patched in version 33.1.0.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/nextcloud/android/pull/16896
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-2w7v-5
- https://hackerone.com/reports/3625210
FAQ
What is CVE-2026-45153?
CVE-2026-45153 is a vulnerability with a CVSS score of 4.6 (MEDIUM). Nextcloud is an open source content collaboration platform. From version 33.0.0 to before version 33.1.0, after unlocking a locked Android phone the back-button could be used to bypass the Nextcloud F...
How severe is CVE-2026-45153?
CVE-2026-45153 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-45153?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.