{"api_version":"1","generated_at":"2026-06-01T22:31:35+00:00","cve":"CVE-2026-45543","urls":{"html":"https://cve.report/CVE-2026-45543","api":"https://cve.report/api/cve/CVE-2026-45543.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-45543","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-45543"},"summary":{"title":"Nextcloud: Deleting a Forms collaborator share leaves uploaded response files accessible through a lingering Files share","description":"Nextcloud is an open source content collaboration platform. From version 4.3.0 to before version 5.2.7, a removed collaborator retains unauthorized read access to uploaded respondent files for the affected form. The scope is limited to uploaded files for forms where that user previously had results access. This issue has been patched in version 5.2.7.","state":"PUBLISHED","assigner":"GitHub_M","published_at":"2026-06-01 19:16:51","updated_at":"2026-06-01 19:16:51"},"problem_types":["CWE-552","CWE-552 CWE-552: Files or Directories Accessible to External Parties"],"metrics":[{"version":"3.1","source":"security-advisories@github.com","type":"Secondary","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","version":"3.1"}}],"references":[{"url":"https://github.com/nextcloud/forms/pull/3291","name":"https://github.com/nextcloud/forms/pull/3291","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/nextcloud/security-advisories/security/advisories/GHSA-q4fw-6jf8-5vhh","name":"https://github.com/nextcloud/security-advisories/security/advisories/GHSA-q4fw-6jf8-5vhh","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://hackerone.com/reports/3617352","name":"https://hackerone.com/reports/3617352","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-45543","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45543","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"nextcloud","product":"security-advisories","version":"affected >= 4.3.0, < 5.2.7","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"product":"security-advisories","vendor":"nextcloud","versions":[{"status":"affected","version":">= 4.3.0, < 5.2.7"}]}],"descriptions":[{"lang":"en","value":"Nextcloud is an open source content collaboration platform. From version 4.3.0 to before version 5.2.7, a removed collaborator retains unauthorized read access to uploaded respondent files for the affected form. The scope is limited to uploaded files for forms where that user previously had results access. This issue has been patched in version 5.2.7."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-552","description":"CWE-552: Files or Directories Accessible to External Parties","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-06-01T17:00:48.861Z","orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M"},"references":[{"name":"https://github.com/nextcloud/security-advisories/security/advisories/GHSA-q4fw-6jf8-5vhh","tags":["x_refsource_CONFIRM"],"url":"https://github.com/nextcloud/security-advisories/security/advisories/GHSA-q4fw-6jf8-5vhh"},{"name":"https://github.com/nextcloud/forms/pull/3291","tags":["x_refsource_MISC"],"url":"https://github.com/nextcloud/forms/pull/3291"},{"name":"https://hackerone.com/reports/3617352","tags":["x_refsource_MISC"],"url":"https://hackerone.com/reports/3617352"}],"source":{"advisory":"GHSA-q4fw-6jf8-5vhh","discovery":"UNKNOWN"},"title":"Nextcloud: Deleting a Forms collaborator share leaves uploaded response files accessible through a lingering Files share"}},"cveMetadata":{"assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","assignerShortName":"GitHub_M","cveId":"CVE-2026-45543","datePublished":"2026-06-01T17:00:48.861Z","dateReserved":"2026-05-12T17:48:47.879Z","dateUpdated":"2026-06-01T17:00:48.861Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-06-01 19:16:51","lastModifiedDate":"2026-06-01 19:16:51","problem_types":["CWE-552","CWE-552 CWE-552: Files or Directories Accessible to External Parties"],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"45543","Ordinal":"1","Title":"Nextcloud: Deleting a Forms collaborator share leaves uploaded r","CVE":"CVE-2026-45543","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"45543","Ordinal":"1","NoteData":"Nextcloud is an open source content collaboration platform. From version 4.3.0 to before version 5.2.7, a removed collaborator retains unauthorized read access to uploaded respondent files for the affected form. The scope is limited to uploaded files for forms where that user previously had results access. This issue has been patched in version 5.2.7.","Type":"Description","Title":"Nextcloud: Deleting a Forms collaborator share leaves uploaded r"}]}}}