VulnerabilityAnalyzed
CVE-2026-45278
From version 6.1.0 to before version 8.2.2, an attacker can craft links that would redirect users to another website, when the victim uses the attackers link to log in via user OIDC.
MEDIUM 6.1EPSS 0.23%
Does this matter?
Lower severity and a low EPSS score (0.23%). Track it; it rarely justifies an emergency change on its own.
Description
Nextcloud is an open source content collaboration platform. From version 6.1.0 to before version 8.2.2, an attacker can craft links that would redirect users to another website, when the victim uses the attackers link to log in via user OIDC. This issue has been patched in version 8.2.2.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.23% probability · 14th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-601
- Affected
- nextcloud/user oidc
- Source
- security-advisories@github.com
References
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-8wjr-5cg8-4w73Vendor Advisory
- https://github.com/nextcloud/user_oidc/pull/1273Issue Tracking, Patch
- https://hackerone.com/reports/3464925Permissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.