CVE-2026-45284: Nextcloud: Wrong condition in the User OIDC app's LdapService allowed deleted LDAP users to authenticate
Nextcloud is an open source content collaboration platform. From version 1.3.6 to before version 8.4.0, an improper check allowed users that where provided by LDAP to still authenticate towards user OIDC after they where deleted. This issue has been patched in version 8.4.0.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45284?
CVE-2026-45284 has a high severity score of 8.8.
How do I fix CVE-2026-45284?
To fix CVE-2026-45284, you need to patch your Nextcloud installation to version 8.4.0 or later.
What vulnerability does CVE-2026-45284 address?
CVE-2026-45284 addresses a vulnerability that allows deleted LDAP users to still authenticate via the User OIDC app in Nextcloud.
What versions are affected by CVE-2026-45284?
CVE-2026-45284 affects Nextcloud versions from 1.3.6 up to, but not including, 8.4.0.
What is the potential impact of CVE-2026-45284?
The potential impact of CVE-2026-45284 is that unauthorized access could be granted to users who have been deleted from LDAP.