CVE-2026-45277
נמוכה 3.3
תיאור (מקור, אנגלית)
Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, authenticated users can check if arbitrary files are associated with specific approval workflows where they can request approval. This issue has been patched in version 2.7.2.
מדדים
- CVSS 3.1
-
3.3 (LOW)
מקור הציון: CNA
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-7/8/2026
- CWE
- CWE-200
מוצרים מושפעים
nextcloud: approval
קישורים
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-h7gm… MitigationVendor Advisory
- https://github.com/nextcloud/approval/pull/356 Issue TrackingPatch
- https://hackerone.com/reports/3475210 Permissions Required