Executive brief
Nextcloud is an open-source platform used by organizations for file sharing and collaboration. A security flaw in its identity management component allowed unauthorized parties to impersonate any user on the system. This could lead to a complete takeover of user accounts and unauthorized access to sensitive corporate data.
Technical details
An authentication bypass vulnerability exists in the Nextcloud User OIDC application due to missing JWT signature verification during the ID4me login flow. The root cause is the failure to validate the authenticity of identity tokens provided by an ID4me authority. A remote attacker controlling a malicious ID4me authority can exploit this by providing unverified claims, allowing them to identify as and log in as any user on the platform. The vulnerability requires minimal user interaction (initiating a login) and is reachable over the network. Patches are available in versions 3.1.0, 4.1.0, 5.1.0, 6.4.0, and 8.3.0.
Affected products
- Nextcloud User OIDC 0.3.0 to < 3.1.0, 5.0.0 to < 5.1.0, 6.0.0 to < 6.4.0
Timeline
- 2026-01-12: patched: Pull request to validate ID4me signatures merged
- 2026-05-12: advisory: GitHub Security Advisory published
- 2026-06-01: disclosed: NVD publication date