Vulnerability Description
Nextcloud is an open source content collaboration platform. Prior to versions 21.1.10, 22.0.11, and 23.0.3, a low-privileged user can force other user's microphones to be muted in calls when no High-performance Backend is installed. This issue has been patched in versions 21.1.10, 22.0.11, and 23.0.3.
CVSS Score
LOW
Related Weaknesses (CWE)
References
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-x75r-6
- https://github.com/nextcloud/spreed/pull/17577
- https://hackerone.com/reports/3636758
FAQ
What is CVE-2026-45266?
CVE-2026-45266 is a vulnerability with a CVSS score of 3.5 (LOW). Nextcloud is an open source content collaboration platform. Prior to versions 21.1.10, 22.0.11, and 23.0.3, a low-privileged user can force other user's microphones to be muted in calls when no High-p...
How severe is CVE-2026-45266?
CVE-2026-45266 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-45266?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.