Junglewise Threat Intelligence

CVE-2026-45284: Nextcloud User OIDC improper access control for deleted LDAP users

CVE-2026-45284 · Severity: medium · CVSS 4.6 · Published 2026-06-01

Technologies: Nextcloud User OIDC. Vendors: Nextcloud.

Executive brief

Nextcloud is an open-source content collaboration platform used for file sharing and communication. A security flaw in the platform's identity management system allowed users who were deleted from a central corporate directory (LDAP) to continue accessing the system via OpenID Connect (OIDC). This could allow former employees or unauthorized individuals to maintain access to sensitive corporate data and collaboration tools after their accounts should have been deactivated.

Technical details

An improper access control vulnerability exists in the Nextcloud User OIDC app's LdapService. The root cause is a logic error in the `isLdapDeletedUser` check, which failed to correctly verify the status of users synchronized via LDAP when they attempted to authenticate using OpenID Connect (OIDC). Consequently, users deleted from the LDAP directory could still successfully authenticate and maintain access to the Nextcloud instance. Exploitation requires the attacker to have a pre-existing account that was deleted from LDAP but remains valid in the OIDC provider's context. The issue is resolved in version 8.4.0 by ensuring the service correctly identifies deleted LDAP users.

Affected products

  • Nextcloud User OIDC app for Nextcloud >= 1.3.6, < 8.4.0

Timeline

  • 2026-02-19: patched: Fix merged into main branch via pull request 1340
  • 2026-05-12: advisory: GitHub Security Advisory GHSA-79xf-ffj8-96fm published
  • 2026-06-01: disclosed: CVE-2026-45284 published to NVD

References

Related threats