Vulnerability Description
Nextcloud is an open source content collaboration platform. From version 0.8.0 to before version 1.0.4, the view filter criteria is exposed to users with read-only permissions in Nextcloud Tables. This issue has been patched in versions 1.0.4 and 2.0.0.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nextcloud | Tables | >= 0.8.0, < 1.0.4 |
Related Weaknesses (CWE)
References
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-vvxm-6MitigationVendor Advisory
- https://github.com/nextcloud/tables/pull/2312Issue TrackingPatch
- https://hackerone.com/reports/3483753Permissions Required
FAQ
What is CVE-2026-45544?
CVE-2026-45544 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Nextcloud is an open source content collaboration platform. From version 0.8.0 to before version 1.0.4, the view filter criteria is exposed to users with read-only permissions in Nextcloud Tables. Thi...
How severe is CVE-2026-45544?
CVE-2026-45544 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-45544?
Check the references section above for vendor advisories and patch information. Affected products include: Nextcloud Tables.