CVE-2026-45544: Nextcloud: Information Disclosure of view filter metdata via Broken Sensitive Data Masking in ViewService
Nextcloud is an open source content collaboration platform. From version 0.8.0 to before version 1.0.4, the view filter criteria is exposed to users with read-only permissions in Nextcloud Tables. This issue has been patched in versions 1.0.4 and 2.0.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Nextcloud Tables / ViewServiceto a version that resolves this vulnerability.Fixed in 1.0.4 - Upgrade
Upgrade
Nextcloud Tables / ViewServiceto a version that resolves this vulnerability.Fixed in 2.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45544?
The severity of CVE-2026-45544 is rated as medium with a score of 4.3.
How do I fix CVE-2026-45544?
To fix CVE-2026-45544, upgrade Nextcloud to version 1.0.4 or later.
What type of vulnerability is CVE-2026-45544?
CVE-2026-45544 is an information disclosure vulnerability due to broken sensitive data masking.
What versions of Nextcloud are affected by CVE-2026-45544?
CVE-2026-45544 affects Nextcloud versions from 0.8.0 to before 1.0.4.
What kind of data is exposed in CVE-2026-45544?
CVE-2026-45544 exposes view filter criteria to users with read-only permissions.