CVE-2026-45278
Nextcloud: Open Redirect in user_oidc login flow via protocol-relative URL bypass
Vexday Risk Score
8Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 3.3EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
01 jun 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Nextcloud is an open source content collaboration platform. From version 6.1.0 to before version 8.2.2, an attacker can craft links that would redirect users to another website, when the victim uses the attackers link to log in via user OIDC. This issue has been patched in version 8.2.2.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Productos afectados
nextcloud · security-advisories¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →