Description
Nextcloud is an open source content collaboration platform. From versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, when a user shares a folder or file with a Nextcloud Team that includes an external member (a person added via email address who does not have a Nextcloud account), the system automatically creates a public link for that external member. This public link is not displayed in the share section of the folder, so the folder owner has no knowledge of its existence. It is sent via email to the external member. It grants the same permissions (read, write, delete, reshare, download) as the Team’s access. An attacker who receives or intercepts this link can access, modify, delete, reshare, and download all data in the shared folder without any further authentication. The folder owner cannot see or revoke the link through the normal sharing interface. This issue has been patched in versions 32.0.9 and 33.0.3.
Published: 2026-06-01
Score: 6.4 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unexpected public link is automatically generated when a folder or file is shared with a Nextcloud Team that includes an external member. The private link is not displayed to the folder owner and is sent via email to the external member. The link grants the same level of access—read, write, delete, reshare, and download—as the Team’s permissions. Because it is not visible or revocable through the normal sharing interface, an attacker who gets or intercepts the link can read, change, delete, reshare, and download any data in the shared folder. This flaw arises from a missing authorization check during link creation, classified as CWE‑862.

Affected Systems

The issue affects Nextcloud versions 32.0.0 through 32.0.8 and 33.0.0 through 33.0.2. Any installation that allows Teams to include users via email addresses that lack a Nextcloud account is vulnerable. The flaw is specific to sharing actions initiated by users with Team access rights. Owners of the shared folder cannot see or revoke the hidden link via the regular interface until the fix is applied.

Risk and Exploitability

The CVSS score is 6.4, indicating a moderate level of severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires that an attacker be able to receive or obtain the automated email containing the link, or otherwise intercept it in transit. An attacker who obtains the link can perform full read, write, delete, reshare, and download actions on all items within the shared folder, giving them essentially the same privileges as the Team member who received the link. Because the link is hidden from the folder owner, the risk of unauthorized disclosure or modification is significant.

Generated by OpenCVE AI on June 1, 2026 at 20:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Nextcloud 32.0.9 or 33.0.3 or later to apply the patch that prevents the automatic creation of hidden public links.
  • Review and disable Team external member sharing for users that require higher security.
  • Audit existing public links that may have been created inadvertently and revoke or delete them manually.

Generated by OpenCVE AI on June 1, 2026 at 20:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 01 Jun 2026 19:00:00 +0000

Type Values Removed Values Added
Description Nextcloud is an open source content collaboration platform. From versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, when a user shares a folder or file with a Nextcloud Team that includes an external member (a person added via email address who does not have a Nextcloud account), the system automatically creates a public link for that external member. This public link is not displayed in the share section of the folder, so the folder owner has no knowledge of its existence. It is sent via email to the external member. It grants the same permissions (read, write, delete, reshare, download) as the Team’s access. An attacker who receives or intercepts this link can access, modify, delete, reshare, and download all data in the shared folder without any further authentication. The folder owner cannot see or revoke the link through the normal sharing interface. This issue has been patched in versions 32.0.9 and 33.0.3.
Title Nextcloud: Hidden Public Link creation when sharing to a Team External Member
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-06-01T16:57:50.447Z

Reserved: 2026-05-11T20:14:43.200Z

Link: CVE-2026-45285

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-01T19:16:50.807

Modified: 2026-06-01T19:16:50.807

Link: CVE-2026-45285

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-01T20:45:25Z

Weaknesses