A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-45285

CVE-2026-45285: Nextcloud Server Auth Bypass Vulnerability

CVE-2026-45285 is an authentication bypass flaw in Nextcloud Server that creates hidden public links when sharing with external team members. Attackers can access shared data without authentication. Learn about affected versions, security impact, and available patches.

Published: June 4, 2026

CVE-2026-45285 Overview

CVE-2026-45285 is a missing authorization vulnerability [CWE-862] in Nextcloud Server affecting the Teams (formerly Circles) sharing feature. When a user shares a folder or file with a Nextcloud Team containing an external member added by email, the system silently generates a public link and emails it to that external member. The link grants read, write, delete, reshare, and download permissions but never appears in the share dialog. Folder owners cannot see or revoke the link through the standard sharing interface. Any attacker who receives or intercepts the email gains full access to the shared content without authentication.

Critical Impact

Hidden public links bypass the Nextcloud sharing UI and grant full read, write, delete, and reshare access to anyone who obtains the link, with no path for the owner to detect or revoke access.

Affected Products

  • Nextcloud Server 32.0.0 through versions before 32.0.9
  • Nextcloud Server 33.0.0 through versions before 33.0.3
  • Nextcloud Enterprise Server (same affected version ranges)

Discovery Timeline

  • 2026-06-01 - CVE-2026-45285 published to NVD
  • 2026-06-03 - Last updated in NVD database

Technical Details for CVE-2026-45285

Vulnerability Analysis

The flaw resides in the Nextcloud circles application that powers the Teams feature. When a Team contains an external member, identified solely by email address rather than a Nextcloud account, the share workflow cannot grant access through the normal user-to-user sharing model. To deliver the content, the application automatically provisions a public share link and emails it to the external recipient.

This automatically generated link inherits the Team's permission set, including write, delete, reshare, and download capabilities. The link is not registered against the folder's visible share list, breaking the assumption that the share UI represents all active access grants. The folder owner has no indication that a public link exists, cannot audit it, and cannot revoke it without administrative database access.

Exploitation requires user interaction and access to the recipient's email channel, which limits exposure on the network. However, intercepted, forwarded, or leaked emails containing the link grant immediate full access to the underlying data.

Root Cause

The root cause is missing authorization enforcement on the share creation path for external Team members. The circles component creates a public share token without surfacing it to the access control layer used by the sharing UI. The owner's authorization scope and visibility are decoupled from the actual share state in the database.

Attack Vector

An attacker obtains the public link from email interception, mail relay logs, accidental forwarding, or compromise of the external recipient's mailbox. The attacker then issues HTTP requests to the Nextcloud public share endpoint using the token embedded in the link. No credentials are required, and the actions taken (modify, delete, reshare) are logged as activity on the public share rather than tied to an authenticated identity.

No verified proof-of-concept code is published. Reproduction requires configuring a Team with an external email member and sharing a folder with that Team, then observing the link delivered in the outbound email.

Detection Methods for CVE-2026-45285

Indicators of Compromise

  • Outbound emails from the Nextcloud instance containing public share URLs addressed to external recipients shortly after Team-based folder shares
  • Public share tokens present in the oc_share database table that are not visible in the folder owner's share UI
  • Anonymous access events in Nextcloud activity logs targeting Team-shared folders, including file modification or deletion actions tied to a public share token

Detection Strategies

  • Query the Nextcloud database for rows in oc_share where share_type indicates a public link and the parent share originated from a Team containing email-only members
  • Correlate circles application logs with mail transport logs to identify automatically generated public link emails sent to external addresses
  • Audit access logs for requests to /s/<token> endpoints that perform write, delete, or reshare operations on Team-shared paths

Monitoring Recommendations

  • Enable verbose logging on the files_sharing and circles applications and forward events to a centralized log platform
  • Alert on any public share creation event where the originating share was made to a Team rather than to an individual user
  • Track outbound SMTP traffic from the Nextcloud server for messages containing public share URLs and review recipient domains

How to Mitigate CVE-2026-45285

Immediate Actions Required

  • Upgrade Nextcloud Server to version 32.0.9 or 33.0.3 depending on the deployed branch
  • Inventory all Teams that include external email members and review historical shares made to those Teams
  • Audit the oc_share table for hidden public links created on behalf of external Team members and revoke any that are no longer required

Patch Information

The issue is patched in Nextcloud Server 32.0.9 and 33.0.3. The fix is implemented in the circles application via Nextcloud circles pull request #2454. Full advisory details are available in the Nextcloud GHSA-r3xh-x86g-hw4m security advisory and the HackerOne report #3625932.

Workarounds

  • Restrict Team membership to users with Nextcloud accounts and remove all email-only external members until the patch is applied
  • Disable the Teams (circles) application in the Nextcloud admin panel if it is not in active use
  • Configure the share-by-mail and public link sharing policies to require password protection and expiration dates to limit exposure of any links that are generated

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeAuth Bypass

  • Vendor/TechNextcloud

  • SeverityMEDIUM

  • CVSS Score6.4

  • EPSS Probability0.04%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N
  • Impact Assessment
  • ConfidentialityHigh
  • IntegrityHigh
  • AvailabilityNone
  • CWE References
  • CWE-862
  • Technical References
  • HackerOne Report #3625932
  • Vendor Resources
  • GitHub Pull Request Update

  • GitHub Security Advisory
  • Related CVEs
  • CVE-2026-45284: Nextcloud User OIDC Auth Bypass Flaw

  • CVE-2026-45281: Nextcloud Server Auth Bypass Vulnerability

  • CVE-2026-45282: Nextcloud Server Auth Bypass Vulnerability

  • CVE-2026-45283: Nextcloud Server Auth Bypass Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English