Nextcloud Server before 9.0.54 and 10.0.0 suffers from an improper authorization check on removing shares
Published Mar 28, 2017
4.3
MEDIUMCVSS 3.0
EPSS 1.62%
Description
Nextcloud Server before 9.0.54 and 10.0.0 suffers from an improper authorization check on removing shares. The Sharing Backend as implemented in Nextcloud does differentiate between shares to users and groups. In case of a received group share, users should be able to unshare the file to themselves but not to the whole group. The previous API implementation simply unshared the file to all users in the group.
Affected products
- Vendor n/a Product Nextcloud Server Nextcloud Server before 9.0.54 and 10.0.0 Defaultn/a
- Version Nextcloud Server Nextcloud Server before 9.0.54 and 10.0.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Nextcloud Server Nextcloud Server before 9.0.54 and 10.0.0 | n/a |
|
- < 9.0.54
- 10.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
AV:N/AC:L/Au:S/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.62% (0.01624) | 75.25th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.62% (0.01624) | 72.92th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.43% (0.00429) | 60.38th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.16% (0.00160) | 53.96th | v3 (v2023.03.01) |
| Jun 26, 2024 | 0.16% (0.00160) | 52.85th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.16% (0.00160) | 50.84th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.03% (0.01034) | 41.69th | v2 (v2022.01.01) |
| Sep 10, 2022 | 1.03% (0.01034) | 39.91th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.03% (0.01034) | 37.91th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.03% (0.01034) | 20.32th | v2 (v2022.01.01) |
References (7)
- http://www.securityfocus.com/bid/97287 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://github.com/nextcloud/server/commit/3387e5d00fcf6b2ea6b285a091e5743f545e7202 x_refsource_MISCIssue TrackingPatchThird Party Advisory
- https://github.com/nextcloud/server/commit/7289cb5ec0b812992ab0dfb889744b94bc0994f0 x_refsource_MISCIssue TrackingPatchThird Party Advisory
- https://github.com/nextcloud/server/commit/a5471b4a3e3f30e99e4de39c97c0c3b3c2f1618f x_refsource_MISCIssue TrackingPatchThird Party Advisory
- https://github.com/nextcloud/server/commit/e2c4f4f9aa11bc92e8f2212cce73841b922187e8 x_refsource_MISCIssue TrackingPatchThird Party Advisory
- https://hackerone.com/reports/153905 x_refsource_MISCExploitThird Party Advisory
- https://nextcloud.com/security/advisory/?id=nc-sa-2016-007 x_refsource_MISCPatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/97287 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://github.com/nextcloud/server/commit/3387e5d00fcf6b2ea6b285a091e5743f545e7202 | x_refsource_MISCIssue TrackingPatchThird Party Advisory | |
| https://github.com/nextcloud/server/commit/7289cb5ec0b812992ab0dfb889744b94bc0994f0 | x_refsource_MISCIssue TrackingPatchThird Party Advisory | |
| https://github.com/nextcloud/server/commit/a5471b4a3e3f30e99e4de39c97c0c3b3c2f1618f | x_refsource_MISCIssue TrackingPatchThird Party Advisory | |
| https://github.com/nextcloud/server/commit/e2c4f4f9aa11bc92e8f2212cce73841b922187e8 | x_refsource_MISCIssue TrackingPatchThird Party Advisory | |
| https://hackerone.com/reports/153905 | x_refsource_MISCExploitThird Party Advisory | |
| https://nextcloud.com/security/advisory/?id=nc-sa-2016-007 | x_refsource_MISCPatchVendor Advisory |
Change history (0)
No recorded changes yet.