Impact
Nextcloud allows users who have only READ and CREATE permissions on a team folder, but lack UPDATE rights, to rename files inside that folder. This privilege escalation flaw means an attacker can change file names, potentially disrupting workflows or renaming critical files without proper authorization. The weakness is categorized as a broken access control (CWE‑284).
Affected Systems
Nextcloud versions 17.0.0 through 17.0.14, 18.0.0 through 18.1.11, 19.0.0 through 19.1.15, 20.0.0 through 20.1.10, and 21.0.0 through 21.0.3 are vulnerable. The defect was fixed in 17.0.15, 18.1.12, 19.1.16, 20.1.11, and 21.0.4.
Risk and Exploitability
The CVSS score of 4.3 indicates low severity. No EPSS data is available, and the vulnerability is not listed in CISA KEV. Exploitation requires authenticated access to a team folder with READ and CREATE permissions; thus the attack vector is internal. The issue enables unauthorized file renaming, affecting the integrity of data within the team folder but not providing broader system compromise.
OpenCVE Enrichment