CVE-2026-77165 PUBLISHED

Assigner: hackerone
Reserved: 20.08.2026 Published: 21.09.2026 Updated: 21.09.2026

File owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no recovery path outside of the database.

Metrics

CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS Score: 6.5

Product Status

Vendor Nextcloud
Product Server
Versions Default: unaffected
  • affected from 32.0.0 to 34.0.0 (incl.)

Credits

  • rz1027 (rz1027) finder

References

Problem Types

  • CWE-284 Improper Access Control - Generic CWE