CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

[NEW] [medium] Nextcloud: Multiple Vulnerabilities

mediumCVE-2026-61527CVE-2026-61545
A remote, authenticated attacker can exploit multiple vulnerabilities in Nextcloud to bypass security precautions and disclose information.

CSIRTS triage

What
Multiple vulnerabilities enable authenticated attackers to bypass security controls and disclose sensitive information.
Who is affected
Nextcloud deployments accessible to authenticated users.
Urgency
Medium urgency; vulnerabilities require authentication but enable privilege escalation and data leakage.
Action
Apply security patches for CVE-2026-61527 and CVE-2026-61545 when released by Nextcloud.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Nextcloud

Get an email when a new Nextcloud advisory drops — max one per day, one-click unsubscribe.

Details

Source
CERT-Bund (BSI) Security Advisories (DE · national-cert · site)
Severity
medium
Published
2026-08-06
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2685

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-61527coverage & exploitation statusNVD · CVE.org
CVE-2026-61545coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Nextcloud

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from CERT-Bund (BSI) Security Advisories