Junglewise Threat Intelligence

CVE-2026-45154: Nextcloud Collectives improper access control in trash bin

CVE-2026-45154 · Severity: low · CVSS 2.6 · Published 2026-06-01

Vendors: Nextcloud.

Executive brief

Nextcloud Collectives is a collaborative document editing tool. A security flaw allowed guest users with 'view-only' permissions to access deleted pages within the trash bin that they should not have been able to see. This could lead to the unauthorized disclosure of sensitive information that was intended to be removed from the platform.

Technical details

An improper access control vulnerability (CWE-284) exists in the Nextcloud Collectives app from version 2.6.0 to before 4.3.0. When a collective is shared with view-only permissions, the system fails to properly restrict guest access to the trash bin component. Consequently, guests can directly access and view pages that have been deleted. Exploitation requires the attacker to have guest access to a shared collective and involves high complexity/user interaction as per the CVSS string, likely related to discovering the direct path to the deleted resources. The issue is resolved in version 4.3.0.

Affected products

  • Nextcloud Collectives >= 2.6.0, < 4.3.0

Timeline

  • 2026-04-20: patched: Pull request merged to fix trash action handling.
  • 2026-05-12: advisory: Vendor security advisory published.
  • 2026-06-01: disclosed: CVE published to NVD.

References