Executive brief
Nextcloud Tables, a tool for managing structured data within the Nextcloud collaboration platform, contains a vulnerability where data filtering rules are not properly hidden. This allows users who only have permission to view specific parts of a table to see the underlying criteria used to filter that data. While this does not allow unauthorized modification of data, it can lead to the exposure of sensitive metadata or internal logic that should remain restricted.
Technical details
An information disclosure vulnerability exists in the Nextcloud Tables 'ViewService' due to broken sensitive data masking. The application fails to sufficiently limit access to metadata derived from sensitive information, specifically exposing view filter criteria to users who should only have read-only access to the filtered results. An authenticated attacker with network access and low privileges can exploit this to view internal filter logic (CWE-1230). The vulnerability is addressed by ensuring the ViewService returns empty or masked results for filter metadata when accessed by unauthorized users. Patches are available in versions 1.0.4 and 2.0.0.
Affected products
- Nextcloud Tables >=0.8.0, <1.0.4; >=2.0.0 (patched)
Timeline
- 2026-02-12: patched: Fix merged into main branch and backported to stable1.0
- 2026-05-13: advisory: GitHub Security Advisory GHSA-vvxm-6jjp-m9mp published
- 2026-06-01: disclosed: CVE-2026-45544 published to NVD