CVE-2026-45690: Nextcloud: Two-Factor Authentication Bypass via Pending Session Token Replay
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, an authentication bypass vulnerability allowed attackers with knowledge of a user's password to circumvent two-factor authentication (2FA) protections. When a user initiated login with valid credentials on a 2FA-enabled account, the system created a temporary session token before enforcing the second factor challenge. This token could be extracted and replayed via HTTP Basic Authentication to gain unauthorized access to authenticated endpoints. It is recommended that the Nextcloud Server is upgraded to 33.0.3 or 32.0.9. It is recommended that the Nextcloud Enterprise Server is upgraded to 33.0.3, 32.0.9, 31.0.14.5, 30.0.17.9 or 29.0.16.16
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45690?
The severity of CVE-2026-45690 is medium, with a score of 5.9.
How do I fix CVE-2026-45690?
To fix CVE-2026-45690, upgrade Nextcloud Server to version 32.0.9 or 33.0.3 and above.
What is CVE-2026-45690?
CVE-2026-45690 is an authentication bypass vulnerability in Nextcloud that allows attackers to circumvent two-factor authentication protections.
What versions of Nextcloud are affected by CVE-2026-45690?
CVE-2026-45690 affects Nextcloud Server versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3.
What can attackers do with CVE-2026-45690?
Attackers with knowledge of a user's password can exploit CVE-2026-45690 to bypass two-factor authentication and gain unauthorized access.