{"schema_version":1,"title":"Nextcloud Enterprise Server vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 7 vulnerabilities in Nextcloud Enterprise Server: 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-45810, was published on 1 June 2026.","url":"https://junglewise.ai/threats/technologies/nextcloud-enterprise-server","json_url":"https://junglewise.ai/threats/technologies/nextcloud-enterprise-server.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/nextcloud-enterprise-server","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":1,"all_time":7,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":7},"latest":[{"cve":"CVE-2026-45810","cvss":6.8,"slug":"cve-2026-45810-nextcloud-server-authorization-bypass-in-file-comments","title":"Nextcloud Server authorization bypass in file comments","severity":"medium","exploited":false,"published_at":"2026-06-01T19:16:53.357+00:00","url":"https://junglewise.ai/threats/cve-2026-45810-nextcloud-server-authorization-bypass-in-file-comments"},{"cve":"CVE-2026-45691","cvss":5.9,"slug":"cve-2026-45691-nextcloud-server-2fa-bypass-in-dav-endpoints-via-session-cookie","title":"Nextcloud Server 2FA bypass in DAV endpoints via session cookie reuse","severity":"medium","exploited":false,"published_at":"2026-06-01T19:16:52.673+00:00","url":"https://junglewise.ai/threats/cve-2026-45691-nextcloud-server-2fa-bypass-in-dav-endpoints-via-session-cookie"},{"cve":"CVE-2026-45690","cvss":5.9,"slug":"cve-2026-45690-nextcloud-server-2fa-bypass-via-session-token-replay","title":"Nextcloud Server 2FA bypass via session token replay","severity":"medium","exploited":false,"published_at":"2026-06-01T19:16:52.507+00:00","url":"https://junglewise.ai/threats/cve-2026-45690-nextcloud-server-2fa-bypass-via-session-token-replay"},{"cve":"CVE-2026-45285","cvss":6.4,"slug":"cve-2026-45285-nextcloud-server-hidden-public-link-creation-in-teams-sharing","title":"Nextcloud Server hidden public link creation in Teams sharing","severity":"medium","exploited":false,"published_at":"2026-06-01T19:16:50.807+00:00","url":"https://junglewise.ai/threats/cve-2026-45285-nextcloud-server-hidden-public-link-creation-in-teams-sharing"},{"cve":"CVE-2026-45283","cvss":6.3,"slug":"cve-2026-45283-nextcloud-server-improper-authentication-in-files-lock-app","title":"Nextcloud Server improper authentication in files_lock app","severity":"medium","exploited":false,"published_at":"2026-06-01T19:16:50.523+00:00","url":"https://junglewise.ai/threats/cve-2026-45283-nextcloud-server-improper-authentication-in-files-lock-app"},{"cve":"CVE-2026-45282","cvss":6.5,"slug":"cve-2026-45282-nextcloud-server-access-control-bypass-in-text-attachments","title":"Nextcloud Server access control bypass in Text attachments","severity":"medium","exploited":false,"published_at":"2026-06-01T19:16:50.37+00:00","url":"https://junglewise.ai/threats/cve-2026-45282-nextcloud-server-access-control-bypass-in-text-attachments"},{"cve":"CVE-2026-45281","cvss":8.1,"slug":"cve-2026-45281-nextcloud-server-authorization-bypass-in-calendar-delegation","title":"Nextcloud Server authorization bypass in calendar delegation","severity":"high","exploited":false,"published_at":"2026-06-01T19:16:50.193+00:00","url":"https://junglewise.ai/threats/cve-2026-45281-nextcloud-server-authorization-bypass-in-calendar-delegation"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Nextcloud Server","slug":"nextcloud-server","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/nextcloud-server"},{"name":"Nextcloud Forms","slug":"forms","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/forms"},{"name":"Nextcloud Approval","slug":"approval","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/approval"},{"name":"Nextcloud Tables","slug":"tables","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/tables"},{"name":"Nextcloud User OIDC","slug":"user-oidc","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/user-oidc"}],"technology":{"hub":true,"name":"Nextcloud Enterprise Server","slug":"nextcloud-enterprise-server","vendor":{"name":"Nextcloud","slug":"nextcloud","url":"https://junglewise.ai/threats/vendors/nextcloud"},"aliases":[],"category":"web-server","homepage":"https://nextcloud.com/enterprise/","repo_url":"https://github.com/nextcloud/server","description":"A self-hosted content collaboration platform designed for enterprise environments.","url":"https://junglewise.ai/threats/technologies/nextcloud-enterprise-server"},"most_severe":[{"cve":"CVE-2026-45281","cvss":8.1,"slug":"cve-2026-45281-nextcloud-server-authorization-bypass-in-calendar-delegation","title":"Nextcloud Server authorization bypass in calendar delegation","severity":"high","exploited":false,"published_at":"2026-06-01T19:16:50.193+00:00","url":"https://junglewise.ai/threats/cve-2026-45281-nextcloud-server-authorization-bypass-in-calendar-delegation"},{"cve":"CVE-2026-45810","cvss":6.8,"slug":"cve-2026-45810-nextcloud-server-authorization-bypass-in-file-comments","title":"Nextcloud Server authorization bypass in file comments","severity":"medium","exploited":false,"published_at":"2026-06-01T19:16:53.357+00:00","url":"https://junglewise.ai/threats/cve-2026-45810-nextcloud-server-authorization-bypass-in-file-comments"},{"cve":"CVE-2026-45282","cvss":6.5,"slug":"cve-2026-45282-nextcloud-server-access-control-bypass-in-text-attachments","title":"Nextcloud Server access control bypass in Text attachments","severity":"medium","exploited":false,"published_at":"2026-06-01T19:16:50.37+00:00","url":"https://junglewise.ai/threats/cve-2026-45282-nextcloud-server-access-control-bypass-in-text-attachments"},{"cve":"CVE-2026-45285","cvss":6.4,"slug":"cve-2026-45285-nextcloud-server-hidden-public-link-creation-in-teams-sharing","title":"Nextcloud Server hidden public link creation in Teams sharing","severity":"medium","exploited":false,"published_at":"2026-06-01T19:16:50.807+00:00","url":"https://junglewise.ai/threats/cve-2026-45285-nextcloud-server-hidden-public-link-creation-in-teams-sharing"},{"cve":"CVE-2026-45283","cvss":6.3,"slug":"cve-2026-45283-nextcloud-server-improper-authentication-in-files-lock-app","title":"Nextcloud Server improper authentication in files_lock app","severity":"medium","exploited":false,"published_at":"2026-06-01T19:16:50.523+00:00","url":"https://junglewise.ai/threats/cve-2026-45283-nextcloud-server-improper-authentication-in-files-lock-app"},{"cve":"CVE-2026-45691","cvss":5.9,"slug":"cve-2026-45691-nextcloud-server-2fa-bypass-in-dav-endpoints-via-session-cookie","title":"Nextcloud Server 2FA bypass in DAV endpoints via session cookie reuse","severity":"medium","exploited":false,"published_at":"2026-06-01T19:16:52.673+00:00","url":"https://junglewise.ai/threats/cve-2026-45691-nextcloud-server-2fa-bypass-in-dav-endpoints-via-session-cookie"},{"cve":"CVE-2026-45690","cvss":5.9,"slug":"cve-2026-45690-nextcloud-server-2fa-bypass-via-session-token-replay","title":"Nextcloud Server 2FA bypass via session token replay","severity":"medium","exploited":false,"published_at":"2026-06-01T19:16:52.507+00:00","url":"https://junglewise.ai/threats/cve-2026-45690-nextcloud-server-2fa-bypass-via-session-token-replay"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}