CVE-2026-45264
Last modified
CVE-2026-45264 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Nextcloud is an open source content collaboration platform. From versions 17.0.0 to before 17.0.15, 18.0.0 to before 18.1.12, 19.0.0 to before 19.1.16, 20.0.0 to before 20.1.11, and 21.0.0 to before 21.0.4, a user with READ and CREATE permission, but no UPDATE permission for a team folder can rename files in the team folder. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
Nextcloud is an open source content collaboration platform. From versions 17.0.0 to before 17.0.15, 18.0.0 to before 18.1.12, 19.0.0 to before 19.1.16, 20.0.0 to before 20.1.11, and 21.0.0 to before 21.0.4, a user with READ and CREATE permission, but no UPDATE permission for a team folder can rename files in the team folder. This issue has been patched in versions 17.0.15, 18.1.12, 19.1.16, 20.1.11, and 21.0.4.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-45264?
How severe is CVE-2026-45264?
How do I fix CVE-2026-45264?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-45257The KTLS receive path decrypted each record in place, assumi…7.8
- CVE-2026-45258dsp_mmap_single() validated the requested mapping by checkin…7.8
- CVE-2026-45259sigqueue(2) was marked as permitted in capability mode with …6.5
- CVE-2026-4526In EmberZNet v9.0.2 and earlier, malformed global ZCL messag…6.5
- CVE-2026-45260Pimcore is an Open Source Data & Experience Management Platf…8.1
- CVE-2026-45261GitButler is a modern Git-based version control interface fo…9.3
- CVE-2026-45266Nextcloud is an open source content collaboration platform. …3.5
- CVE-2026-45267Nextcloud is an open source content collaboration platform. …6.5
- CVE-2026-4527GitLab has remediated an issue in GitLab CE/EE affecting all…6.5
- CVE-2026-45270CI4MS is a CodeIgniter 4-based content management system ske…8.7
- CVE-2026-45275Nextcloud is an open source content collaboration platform. …6.5
- CVE-2026-45277Nextcloud is an open source content collaboration platform. …3.3
Are you affected by CVE-2026-45264?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
