CVE-2026-45544 PUBLISHED

Nextcloud: Information Disclosure of view filter metdata via Broken Sensitive Data Masking in ViewService

Assigner: GitHub_M
Reserved: 12.05.2026 Published: 01.06.2026 Updated: 01.06.2026

Nextcloud is an open source content collaboration platform. From version 0.8.0 to before version 1.0.4, the view filter criteria is exposed to users with read-only permissions in Nextcloud Tables. This issue has been patched in versions 1.0.4 and 2.0.0.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS Score: 4.3

Product Status

Vendor nextcloud
Product security-advisories
Versions
  • Version >= 0.8.0, < 1.0.4 is affected

References

Problem Types

  • CWE-1230: Exposure of Sensitive Information Through Metadata CWE