Description
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.2, and 33.0.0 to before 33.0.1, the files_lock app did not properly validate the ownership of files when processing DAV lock and unlock requests. An authenticated user could lock or unlock files belonging to other users by targeting their absolute WebDAV paths. Additionally, lock tokens were disclosed to unauthorized callers in error responses, allowing attackers to remove token-based locks placed by other users' client applications. It is recommended that the Nextcloud Server is upgraded to 32.0.2 or 33.0.1. It is recommended that the Nextcloud Enterprise Server is upgraded to 31.0.14.4 or 32.0.2 or 33.0.1
Published: 2026-06-01
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In Nextcloud Server versions 32.0.0 through 32.0.1 and 33.0.0 through 33.0.0, the files_lock application failed to verify that a requesting user owned the file referenced in a WebDAV lock or unlock operation. An authenticated attacker could therefore lock or unlock any file by supplying its absolute path, thereby affecting that file’s availability and potentially disrupting other users’ workflows. In addition, the application exposed lock tokens in error responses, enabling adversaries to acquire tokens that belong to other users and revoke their locks without permission. The flaw represents a misimplementation of access control (CWE‑287) with implications for data integrity and availability.

Affected Systems

Nextcloud Server 32.0.0 up to but not including 32.0.2, and 33.0.0 up to but not including 33.0.1. Nextcloud Enterprise Server versions that have not yet been upgraded to 31.0.14.4, 32.0.2, or 33.0.1 are potentially vulnerable.

Risk and Exploitability

The CVSS score of 6.3 categorizes the vulnerability as moderate, and no EPSS data is publicly available for this issue. The vulnerability is not listed in the CISA KEV catalog, meaning there are no known large‑scale active campaigns. An attacker would need to be an authenticated Nextcloud user on the affected instance – the description indicates that being an authenticated user is the likely attack vector. By sending crafted WebDAV lock or unlock requests to specified paths, the attacker can alter the state of other users' files and retrieve lock tokens for removal of legitimate locks. While the attack does not grant remote code execution, it undermines user control and can serve as a foothold for further lateral movement or denial of service within the Nextcloud environment.

Generated by OpenCVE AI on June 1, 2026 at 21:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Nextcloud Server to version 32.0.2 or 33.0.1
  • Upgrade Nextcloud Enterprise Server to version 31.0.14.4, 32.0.2 or 33.0.1
  • Disable or restrict the Files Lock app until the official patch is applied

Generated by OpenCVE AI on June 1, 2026 at 21:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 01 Jun 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 01 Jun 2026 19:00:00 +0000

Type Values Removed Values Added
Description Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.2, and 33.0.0 to before 33.0.1, the files_lock app did not properly validate the ownership of files when processing DAV lock and unlock requests. An authenticated user could lock or unlock files belonging to other users by targeting their absolute WebDAV paths. Additionally, lock tokens were disclosed to unauthorized callers in error responses, allowing attackers to remove token-based locks placed by other users' client applications. It is recommended that the Nextcloud Server is upgraded to 32.0.2 or 33.0.1. It is recommended that the Nextcloud Enterprise Server is upgraded to 31.0.14.4 or 32.0.2 or 33.0.1
Title Nextcloud: Files Lock app allows users to lock and unlock files of other users
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-06-01T21:42:51.254Z

Reserved: 2026-05-11T18:41:13.158Z

Link: CVE-2026-45283

cve-icon Vulnrichment

Updated: 2026-06-01T21:41:54.940Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-06-01T19:16:50.523

Modified: 2026-06-02T14:00:31.067

Link: CVE-2026-45283

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-01T21:15:15Z

Weaknesses