CVE-2026-45284

Nextcloud is an open source content collaboration platform. From version 1.3.6 to before version 8.4.0, an improper check allowed users that where provided by LDAP to still authenticate towards user OIDC after they where deleted. This issue has been patched in version 8.4.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nextcloud:user_oidc:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-06-01 19:16

Updated : 2026-07-22 08:10


NVD link : CVE-2026-45284

Mitre link : CVE-2026-45284

CVE.ORG link : CVE-2026-45284


JSON object : View

Products Affected

nextcloud

  • user_oidc
CWE
CWE-284

Improper Access Control

NVD-CWE-noinfo