CVE-2026-45691: Nextcloud: Bypass of second factor authentication on DAV endpoints
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, a pre-2FA session cookie (created after successful password authentication but before TOTP completion) could be reused as a Bearer token to authenticate against DAV endpoints, granting read/write access and bypassing mandatory two-factor authentication. It is recommended that the Nextcloud Server is upgraded to 33.0.3 or 32.0.9. It is recommended that the Nextcloud Enterprise Server is upgraded to 33.0.3, 32.0.9, 31.0.14.5, 30.0.17.9 or 29.0.16.16
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45691?
The severity of CVE-2026-45691 is rated as medium with a score of 5.9.
How do I fix CVE-2026-45691?
To fix CVE-2026-45691, upgrade Nextcloud Server to version 32.0.9 or 33.0.3 or later.
What type of vulnerability is CVE-2026-45691?
CVE-2026-45691 is a bypass of second factor authentication on DAV endpoints.
What versions of Nextcloud are affected by CVE-2026-45691?
CVE-2026-45691 affects Nextcloud Server versions 32.0.0 to before 32.0.9 and 33.0.0 to before 33.0.3.
Is there any impact from exploiting CVE-2026-45691?
Exploiting CVE-2026-45691 could allow unauthorized access by reusing a pre-2FA session cookie as a Bearer token.