CVE-2026-45278

Nextcloud is an open source content collaboration platform. From version 6.1.0 to before version 8.2.2, an attacker can craft links that would redirect users to another website, when the victim uses the attackers link to log in via user OIDC. This issue has been patched in version 8.2.2.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nextcloud:user_oidc:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-06-01 19:16

Updated : 2026-07-20 20:10


NVD link : CVE-2026-45278

Mitre link : CVE-2026-45278

CVE.ORG link : CVE-2026-45278


JSON object : View

Products Affected

nextcloud

  • user_oidc
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')