Junglewise Threat Intelligence

CVE-2026-45264: Nextcloud Team Folders improper access control in file renaming

CVE-2026-45264 · Severity: medium · CVSS 4.3 · Published 2026-06-01

Vendors: Nextcloud.

Executive brief

Nextcloud is a content collaboration platform used by organizations to store and share files. A flaw in the Team Folders application allows users who only have permission to read and create files to also rename existing files, even if they lack the specific permission to modify them. This could lead to unauthorized reorganization of shared data or disruption of file-based workflows.

Technical details

An improper access control vulnerability (CWE-284) exists in the Nextcloud Team Folders (Groupfolders) application. The vulnerability stems from insufficient validation of Access Control List (ACL) rules when processing file rename requests. Specifically, the application fails to verify that a user possesses 'UPDATE' permissions before allowing a rename operation, provided the user already has 'READ' and 'CREATE' permissions. An authenticated attacker with network access to the Nextcloud instance can exploit this to rename files in shared team folders where they should only have read/create access. The issue is resolved in versions 17.0.15, 18.1.12, 19.1.16, 20.1.11, and 21.0.4.

Affected products

  • Nextcloud Team Folders (Groupfolders) 17.0.0 to < 17.0.15, 18.0.0 to < 18.1.12, 19.0.0 to < 19.1.16, 20.0.0 to < 20.1.11, 21.0.0 to < 21.0.4

Timeline

  • 2026-02-09: patched: Fix merged into master branch
  • 2026-05-12: advisory: GitHub Security Advisory published
  • 2026-06-01: disclosed: CVE published to NVD

References