Vulnerability Description
Nextcloud is an open source content collaboration platform. From version 2.6.0 to before version 4.3.0, when a previous collective pages was deleted and the collective was shared view-only, guests with access to the collective were able to access the deleted pages directly from the trashbin. This issue has been patched in version 4.3.0.
CVSS Score
LOW
Related Weaknesses (CWE)
References
- https://github.com/nextcloud/collectives/pull/2432
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-8mpv-g
- https://hackerone.com/reports/3521434
FAQ
What is CVE-2026-45154?
CVE-2026-45154 is a vulnerability with a CVSS score of 2.6 (LOW). Nextcloud is an open source content collaboration platform. From version 2.6.0 to before version 4.3.0, when a previous collective pages was deleted and the collective was shared view-only, guests wit...
How severe is CVE-2026-45154?
CVE-2026-45154 has been rated LOW with a CVSS base score of 2.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-45154?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.