Junglewise Threat Intelligence

CVE-2026-77169: Nextcloud Team Folders authorization bypass in workspace app

CVE-2026-77169 · Severity: medium · CVSS 6.5 · Published 2026-09-18

Vendors: Nextcloud.

Executive brief

Nextcloud's Team Folders app (formerly Group Folders) contains an authorization flaw when combined with the Workspace app that allows API/REST-only delegated administrators to access team folders beyond their assigned permissions. This bypasses folder-level access controls, potentially exposing sensitive team data to administrators who should not have full access to those folders.

Technical details

The vulnerability is an authorization bypass in the Team Folders app when integrated with the Workspace app. Delegated administrators configured with API/REST-only privileges and limited folder access can circumvent these folder-level authorization controls through API calls, gaining access to folders they should not be able to manage. The workspace app is designed to restrict administrative privileges to specific folders via API/REST interfaces, but the implementation fails to properly enforce these restrictions. An authenticated API request from a delegated admin is sufficient to trigger the bypass; no special preconditions or user interaction is required.

Affected products

  • Nextcloud Team Folders Unknown

Timeline

  • 2026-09-18: disclosed

References