CVE-2026-45544CWE-1230
Nextcloud: Information Disclosure of view filter metdata via Broken Sensitive Data Masking in ViewService
Medium · published June 1, 2026
What it is
Nextcloud is an open source content collaboration platform. From version 0.8.0 to before version 1.0.4, the view filter criteria is exposed to users with read-only permissions in Nextcloud Tables. This issue has been patched in versions 1.0.4 and 2.0.0.
The record
Technical detail
- CVSS v3.1
- 4.3 · MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- CVSS v4.0
- Not supplied
- EPSS
- 0.00222 · 12.6th percentile
- Weakness
- CWE-1230 · Exposure of Sensitive Information Through Metadata
- Published
- 2026-06-01T17:03Z
EPSS history
Timeline