Description
Nextcloud is an open source content collaboration platform. From version 4.3.0 to before version 5.2.7, a removed collaborator retains unauthorized read access to uploaded respondent files for the affected form. The scope is limited to uploaded files for forms where that user previously had results access. This issue has been patched in version 5.2.7.
Published: 2026-06-01
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Nextcloud Forms versions 4.3.0 through 5.2.6 contain a flaw that lets a removed collaborator retain read access to files that were uploaded as responses to a form. The vulnerability stems from a lingering file‑share that is not cleaned up when the collaborator role is deleted, exposing data that the user once had permission to view. This is a classic case of sensitive data exposure, identified by CWE‑552, and results in the unauthorized disclosure of private files without granting any additional privileges. Based on the description, it is inferred that the likely attack vector is the presence of a lingering file‑share after collaborator removal, which allows the attacker to read files they were previously allowed to see.

Affected Systems

The impacted software is the Nextcloud content collaboration platform, specifically the Forms app. Users running Nextcloud 4.3.0 up to, but not including, version 5.2.7 are affected. The issue is limited to uploaded response files for forms where the deleted collaborator previously had results‑access rights.

Risk and Exploitability

The flaw carries a CVSS score of 5.3, indicating moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, so the current exploitation likelihood is unknown. Attackers would need prior legitimate collaborator access to the form results to achieve the data breach; the vulnerability does not allow arbitrary code execution or full control of the system. Based on the description, it is inferred that the attack vector requires the attacker to first invoke the collaborator removal action, after which the residual file‑share remains accessible.

Generated by OpenCVE AI on June 1, 2026 at 21:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Nextcloud Forms to version 5.2.7 or later, which removes the lingering file‑share bug.
  • If an upgrade is not immediately possible, manually identify and delete any lingering file‑shares associated with removed collaborators within the Files app or via the admin GUI.
  • Audit existing form response files for unusual access and revoke any unexpected shares, and monitor logs for collaborator removal events to ensure the issue is resolved.

Generated by OpenCVE AI on June 1, 2026 at 21:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 04 Jun 2026 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:nextcloud:forms:*:*:*:*:*:*:*:*

Wed, 03 Jun 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Nextcloud
Nextcloud forms
Vendors & Products Nextcloud
Nextcloud forms

Mon, 01 Jun 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 01 Jun 2026 19:00:00 +0000

Type Values Removed Values Added
Description Nextcloud is an open source content collaboration platform. From version 4.3.0 to before version 5.2.7, a removed collaborator retains unauthorized read access to uploaded respondent files for the affected form. The scope is limited to uploaded files for forms where that user previously had results access. This issue has been patched in version 5.2.7.
Title Nextcloud: Deleting a Forms collaborator share leaves uploaded response files accessible through a lingering Files share
Weaknesses CWE-552
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-06-01T19:33:14.762Z

Reserved: 2026-05-12T17:48:47.879Z

Link: CVE-2026-45543

cve-icon Vulnrichment

Updated: 2026-06-01T19:33:08.492Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-01T19:16:51.707

Modified: 2026-06-04T16:43:12.507

Link: CVE-2026-45543

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-02T20:53:42Z

Weaknesses
  • CWE-552

    Files or Directories Accessible to External Parties