Known Vulnerabilities for User Oidc by Nextcloud
Listed below are 6 of the newest known vulnerabilities associated with "User Oidc" by "Nextcloud".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-87853 json | A flaw was found in SSSD's IdP authentication provider. The eval_access_token_buf() function compares the OIDC subject identi... | Not Provided | 2026-09-09 | 2026-09-10 |
| CVE-2026-87011 json | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, the unauthenti... | Not Provided | 2026-09-09 | 2026-09-09 |
| CVE-2026-81029 json | OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued token to it. SamlLoginServl... | Not Provided | 2026-08-26 | 2026-08-26 |
| CVE-2026-77298 json | SeaweedFS is a distributed storage system for files and blobs. In versions 4.39 and earlier, the S3 API accepts an external O... | Not Provided | 2026-08-26 | 2026-08-27 |
| CVE-2026-73419 json | NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth.js s... | Not Provided | 2026-08-12 | 2026-08-13 |
| CVE-2026-72561 json | A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 allows any authenticated non-admini... | Not Provided | 2026-08-11 | 2026-08-11 |
| CVE-2026-67330 json | @better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.0-bet... | Not Provided | 2026-08-01 | 2026-08-03 |
| CVE-2026-65956 json | KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 1.6.15, the SSO configuration API endp... | Not Provided | 2026-08-26 | 2026-08-29 |
| CVE-2026-63094 json | SigNoz before 0.134.0 contains an open redirect vulnerability in the SSO authentication flow that allows unauthenticated atta... | Not Provided | 2026-07-17 | 2026-07-27 |
| CVE-2026-61641 json | Wallos is an open-source, self-hostable personal subscription tracker. From version 4.0.0 to before version 4.9.6, Wallos's O... | Not Provided | 2026-08-31 | 2026-09-01 |