CVE-2026-45283: CWE-287: Improper Authentication in nextcloud security-advisories
Nextcloud Server versions 32.0.0 to before 32.0.2 and 33.0.0 to before 33.0.1 contain an improper authentication vulnerability in the files_lock app. This flaw allows authenticated users to lock or unlock files owned by other users by exploiting absolute WebDAV paths.
AI Analysis
Technical Summary
CVE-2026-45283 is an improper authentication vulnerability (CWE-287) affecting the files_lock app in Nextcloud Server. In affected versions, the app does not properly validate file ownership when handling DAV lock and unlock requests, allowing authenticated users to manipulate locks on files belonging to others via absolute WebDAV paths. Furthermore, lock tokens are disclosed in error responses to unauthorized callers, facilitating the removal of locks placed by other users' client applications. The vulnerability affects Nextcloud Server versions from 32.0.0 up to but not including 32.0.2, and 33.0.0 up to but not including 33.0.1. The CVSS v3.1 base score is 6.3, indicating a medium severity level.
Potential Impact
An authenticated user can bypass proper ownership checks to lock or unlock files belonging to other users, potentially disrupting file access controls. Disclosure of lock tokens in error messages further enables unauthorized removal of locks, which may affect data integrity and collaboration workflows. The impact includes limited confidentiality, integrity, and availability consequences as indicated by the CVSS vector (C:L/I:L/A:L).
Mitigation Recommendations
Upgrading Nextcloud Server to version 32.0.2 or 33.0.1, or Nextcloud Enterprise Server to version 31.0.14.4, 32.0.2, or 33.0.1 is recommended to remediate this vulnerability. Patch status is not explicitly confirmed in the advisory, but the vendor recommends these upgrades as fixes. No alternative mitigations or temporary workarounds are provided.
CVE-2026-45283: CWE-287: Improper Authentication in nextcloud security-advisories
Description
Nextcloud Server versions 32.0.0 to before 32.0.2 and 33.0.0 to before 33.0.1 contain an improper authentication vulnerability in the files_lock app. This flaw allows authenticated users to lock or unlock files owned by other users by exploiting absolute WebDAV paths.
CVSS v3.1
Score 6.3medium
Affected software
pkg:github/nextcloud/files_lockRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-45283 is an improper authentication vulnerability (CWE-287) affecting the files_lock app in Nextcloud Server. In affected versions, the app does not properly validate file ownership when handling DAV lock and unlock requests, allowing authenticated users to manipulate locks on files belonging to others via absolute WebDAV paths. Furthermore, lock tokens are disclosed in error responses to unauthorized callers, facilitating the removal of locks placed by other users' client applications. The vulnerability affects Nextcloud Server versions from 32.0.0 up to but not including 32.0.2, and 33.0.0 up to but not including 33.0.1. The CVSS v3.1 base score is 6.3, indicating a medium severity level.
Potential Impact
An authenticated user can bypass proper ownership checks to lock or unlock files belonging to other users, potentially disrupting file access controls. Disclosure of lock tokens in error messages further enables unauthorized removal of locks, which may affect data integrity and collaboration workflows. The impact includes limited confidentiality, integrity, and availability consequences as indicated by the CVSS vector (C:L/I:L/A:L).
Mitigation Recommendations
Upgrading Nextcloud Server to version 32.0.2 or 33.0.1, or Nextcloud Enterprise Server to version 31.0.14.4, 32.0.2, or 33.0.1 is recommended to remediate this vulnerability. Patch status is not explicitly confirmed in the advisory, but the vendor recommends these upgrades as fixes. No alternative mitigations or temporary workarounds are provided.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-11T18:41:13.158Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a1de306e29bf47b503a557b
Added to database: 06/01/2026, 19:52:38 UTC
Last enriched: 06/08/2026, 20:59:52 UTC
Last updated: 07/31/2026, 19:22:59 UTC
Views: 242
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.