{"api_version":"1","generated_at":"2026-07-23T04:59:00+00:00","cve":"CVE-2016-9464","urls":{"html":"https://cve.report/CVE-2016-9464","api":"https://cve.report/api/cve/CVE-2016-9464.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-9464","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-9464"},"summary":{"title":"CVE-2016-9464","description":"Nextcloud Server before 9.0.54 and 10.0.0 suffers from an improper authorization check on removing shares. The Sharing Backend as implemented in Nextcloud does differentiate between shares to users and groups. In case of a received group share, users should be able to unshare the file to themselves but not to the whole group. The previous API implementation simply unshared the file to all users in the group.","state":"PUBLISHED","assigner":"hackerone","published_at":"2017-03-28 02:59:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-285","CWE-285 Improper Authorization (CWE-285)"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4","severity":"","vector":"AV:N/AC:L/Au:S/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/97287","name":"http://www.securityfocus.com/bid/97287","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Nextcloud CVE-2016-9464 Unauthorized Access Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://nextcloud.com/security/advisory/?id=nc-sa-2016-007","name":"https://nextcloud.com/security/advisory/?id=nc-sa-2016-007","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"advisory – Nextcloud","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/nextcloud/server/commit/7289cb5ec0b812992ab0dfb889744b94bc0994f0","name":"https://github.com/nextcloud/server/commit/7289cb5ec0b812992ab0dfb889744b94bc0994f0","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Patch","Third Party Advisory"],"title":"Do not allow to delete/update group shares as a group member · nextcloud/server@7289cb5 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/nextcloud/server/commit/a5471b4a3e3f30e99e4de39c97c0c3b3c2f1618f","name":"https://github.com/nextcloud/server/commit/a5471b4a3e3f30e99e4de39c97c0c3b3c2f1618f","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Patch","Third Party Advisory"],"title":"Do not allow to delete/update group shares as a group member · nextcloud/server@a5471b4 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://hackerone.com/reports/153905","name":"https://hackerone.com/reports/153905","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"],"title":"HackerOne","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/nextcloud/server/commit/e2c4f4f9aa11bc92e8f2212cce73841b922187e8","name":"https://github.com/nextcloud/server/commit/e2c4f4f9aa11bc92e8f2212cce73841b922187e8","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Patch","Third Party Advisory"],"title":"Add intergration test · nextcloud/server@e2c4f4f · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/nextcloud/server/commit/3387e5d00fcf6b2ea6b285a091e5743f545e7202","name":"https://github.com/nextcloud/server/commit/3387e5d00fcf6b2ea6b285a091e5743f545e7202","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Patch","Third Party Advisory"],"title":"Add intergration test · nextcloud/server@3387e5d · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-9464","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-9464","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"Nextcloud Server Nextcloud Server before 9.0.54 and 10.0.0","version":"affected Nextcloud Server Nextcloud Server before 9.0.54 and 10.0.0","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"9464","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"nextcloud","cpe5":"nextcloud_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"9464","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"nextcloud","cpe5":"nextcloud_server","cpe6":"10.0","cpe7":"rc1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T02:50:38.553Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"https://github.com/nextcloud/server/commit/7289cb5ec0b812992ab0dfb889744b94bc0994f0"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://github.com/nextcloud/server/commit/3387e5d00fcf6b2ea6b285a091e5743f545e7202"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://github.com/nextcloud/server/commit/a5471b4a3e3f30e99e4de39c97c0c3b3c2f1618f"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://github.com/nextcloud/server/commit/e2c4f4f9aa11bc92e8f2212cce73841b922187e8"},{"name":"97287","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/97287"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://nextcloud.com/security/advisory/?id=nc-sa-2016-007"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://hackerone.com/reports/153905"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"Nextcloud Server Nextcloud Server before 9.0.54 and 10.0.0","vendor":"n/a","versions":[{"status":"affected","version":"Nextcloud Server Nextcloud Server before 9.0.54 and 10.0.0"}]}],"datePublic":"2017-03-27T00:00:00.000Z","descriptions":[{"lang":"en","value":"Nextcloud Server before 9.0.54 and 10.0.0 suffers from an improper authorization check on removing shares. The Sharing Backend as implemented in Nextcloud does differentiate between shares to users and groups. In case of a received group share, users should be able to unshare the file to themselves but not to the whole group. The previous API implementation simply unshared the file to all users in the group."}],"problemTypes":[{"descriptions":[{"cweId":"CWE-285","description":"Improper Authorization (CWE-285)","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2017-04-03T09:57:01.000Z","orgId":"36234546-b8fa-4601-9d6f-f4e334aa8ea1","shortName":"hackerone"},"references":[{"tags":["x_refsource_MISC"],"url":"https://github.com/nextcloud/server/commit/7289cb5ec0b812992ab0dfb889744b94bc0994f0"},{"tags":["x_refsource_MISC"],"url":"https://github.com/nextcloud/server/commit/3387e5d00fcf6b2ea6b285a091e5743f545e7202"},{"tags":["x_refsource_MISC"],"url":"https://github.com/nextcloud/server/commit/a5471b4a3e3f30e99e4de39c97c0c3b3c2f1618f"},{"tags":["x_refsource_MISC"],"url":"https://github.com/nextcloud/server/commit/e2c4f4f9aa11bc92e8f2212cce73841b922187e8"},{"name":"97287","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/97287"},{"tags":["x_refsource_MISC"],"url":"https://nextcloud.com/security/advisory/?id=nc-sa-2016-007"},{"tags":["x_refsource_MISC"],"url":"https://hackerone.com/reports/153905"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"support@hackerone.com","ID":"CVE-2016-9464","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Nextcloud Server Nextcloud Server before 9.0.54 and 10.0.0","version":{"version_data":[{"version_value":"Nextcloud Server Nextcloud Server before 9.0.54 and 10.0.0"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Nextcloud Server before 9.0.54 and 10.0.0 suffers from an improper authorization check on removing shares. The Sharing Backend as implemented in Nextcloud does differentiate between shares to users and groups. In case of a received group share, users should be able to unshare the file to themselves but not to the whole group. The previous API implementation simply unshared the file to all users in the group."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Improper Authorization (CWE-285)"}]}]},"references":{"reference_data":[{"name":"https://github.com/nextcloud/server/commit/7289cb5ec0b812992ab0dfb889744b94bc0994f0","refsource":"MISC","url":"https://github.com/nextcloud/server/commit/7289cb5ec0b812992ab0dfb889744b94bc0994f0"},{"name":"https://github.com/nextcloud/server/commit/3387e5d00fcf6b2ea6b285a091e5743f545e7202","refsource":"MISC","url":"https://github.com/nextcloud/server/commit/3387e5d00fcf6b2ea6b285a091e5743f545e7202"},{"name":"https://github.com/nextcloud/server/commit/a5471b4a3e3f30e99e4de39c97c0c3b3c2f1618f","refsource":"MISC","url":"https://github.com/nextcloud/server/commit/a5471b4a3e3f30e99e4de39c97c0c3b3c2f1618f"},{"name":"https://github.com/nextcloud/server/commit/e2c4f4f9aa11bc92e8f2212cce73841b922187e8","refsource":"MISC","url":"https://github.com/nextcloud/server/commit/e2c4f4f9aa11bc92e8f2212cce73841b922187e8"},{"name":"97287","refsource":"BID","url":"http://www.securityfocus.com/bid/97287"},{"name":"https://nextcloud.com/security/advisory/?id=nc-sa-2016-007","refsource":"MISC","url":"https://nextcloud.com/security/advisory/?id=nc-sa-2016-007"},{"name":"https://hackerone.com/reports/153905","refsource":"MISC","url":"https://hackerone.com/reports/153905"}]}}}},"cveMetadata":{"assignerOrgId":"36234546-b8fa-4601-9d6f-f4e334aa8ea1","assignerShortName":"hackerone","cveId":"CVE-2016-9464","datePublished":"2017-03-28T02:46:00.000Z","dateReserved":"2016-11-19T00:00:00.000Z","dateUpdated":"2024-08-06T02:50:38.553Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-03-28 02:59:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-285","CWE-285 Improper Authorization (CWE-285)"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:*","versionEndExcluding":"9.0.54","matchCriteriaId":"D6E3F368-B854-430E-AB8F-496675C4E210"},{"vulnerable":true,"criteria":"cpe:2.3:a:nextcloud:nextcloud_server:10.0:rc1:*:*:*:*:*:*","matchCriteriaId":"A11A2099-3AEC-4622-9ADE-085740EE67C7"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"9464","Ordinal":"1","Title":"CVE-2016-9464","CVE":"CVE-2016-9464","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"9464","Ordinal":"1","NoteData":"Nextcloud Server before 9.0.54 and 10.0.0 suffers from an improper authorization check on removing shares. The Sharing Backend as implemented in Nextcloud does differentiate between shares to users and groups. In case of a received group share, users should be able to unshare the file to themselves but not to the whole group. The previous API implementation simply unshared the file to all users in the group.","Type":"Description","Title":"CVE-2016-9464"},{"CveYear":"2016","CveId":"9464","Ordinal":"2","NoteData":"2017-03-27","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"9464","Ordinal":"3","NoteData":"2017-04-03","Type":"Other","Title":"Modified"}]}}}