Multiple Vulnerabilities in Nextcloud Products Identified

Multiple vulnerabilities have been discovered in Nextcloud products, potentially allowing attackers to compromise data confidentiality and bypass security policies. Affected versions include Mail 3.5.x to 3.7.x prior to 3.7.25, Mail 4.x/5.x prior to 5.5.16, Mail 5.6.x prior to 5.6.20, Mail 5.7.x prior to 5.7.13, and Server versions 32.0.10–32.0.x prior to 32.0.12, 33.0.4–33.0.x prior to 33.0.6, and 34.0.x prior to 34.0.1 for Nextcloud and Nextcloud Enterprise. The vulnerabilities, detailed in security advisories GHSA-99gw-ww6p-f2rr and GHSA-vq3v-jv6f-6xp2, are tracked as CVE-2026-61527 and CVE-2026-61545. Users are advised to apply patches from Nextcloud’s security bulletins to address these issues.

Summary of content from

source

Made by AI. If you spot anything of concern write us at contact@cybach.com. We’ll promptly correct irregularities.


Posted