Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nextcloud
Nextcloud user Oidc |
|
| Vendors & Products |
Nextcloud
Nextcloud user Oidc |
Mon, 01 Jun 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 01 Jun 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nextcloud is an open source content collaboration platform. From versions 0.3.0 to before 3.1.0, 5.0.0 to before 5.1.0, and 6.0.0 to before 6.4.0, a missing signature verification in User OIDC allowed a malicious ID4me authority to identify as any user. This issue has been patched in versions 3.1.0, 4.1.0, 5.1.0, 6.4.0 and 8.3.0. | |
| Title | Nextcloud: Authentication Bypass in ID4me handling via Missing JWT Signature Verification in User OIDC | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-03T03:55:47.564Z
Reserved: 2026-05-08T20:44:38.964Z
Link: CVE-2026-45156
Updated: 2026-06-01T18:12:55.715Z
Status : Deferred
Published: 2026-06-01T17:17:09.283
Modified: 2026-06-01T18:14:29.087
Link: CVE-2026-45156
No data.
OpenCVE Enrichment
Updated: 2026-06-02T20:54:05Z