CVE-2026-45544CWE-1230

Nextcloud: Information Disclosure of view filter metdata via Broken Sensitive Data Masking in ViewService

Medium · published June 1, 2026

CVSS v3.1
4.3
EPSS
0%
Percentile
12.6
In the wild
Unconfirmed
What it is

Nextcloud is an open source content collaboration platform. From version 0.8.0 to before version 1.0.4, the view filter criteria is exposed to users with read-only permissions in Nextcloud Tables. This issue has been patched in versions 1.0.4 and 2.0.0.

The record
Technical detail
CVSS v3.1
4.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00222 · 12.6th percentile
Weakness
CWE-1230 · Exposure of Sensitive Information Through Metadata
Published
2026-06-01T17:03Z
EPSS history
Timeline
  • 01 JUN 17:03Z
    Nextcloud: Information Disclosure of view filter metdata via Broken Sensitive Data Masking in ViewService
    cvelistv5