CVE-2026-45722: Nextcloud: Tables app allows limited SQLi in ORDER BY with malicious sort order argument for Table Views

Published Jun 1, 2026
·
Updated

Nextcloud is an open source content collaboration platform. From versions 0.9.0 to before 0.9.7, and 1.0.0 to before 1.0.2, a missing sanitization in the Tables app allowed a user with access to the tables app to perform a limited SQL injection in the ORDER BY statement of a query. Compared to normal SQL injections, the ORDER BY is limited to extracting a single bit of information per request or to make the database wait for a given time. This issue has been patched in versions 0.9.7 and 1.0.2.

Affected Software

3 affected components
Nextcloud Nextcloud Tables app>=0.9.0<0.9.7, >=1.0.0<1.0.2
Nextcloud Tables Nextcloud>=0.9.0<0.9.7
Nextcloud Tables Nextcloud>=1.0.0<1.0.2

Event History

Jun 1, 2026
CVE Published
via MITRE·05:11 PM
Data Sourced
via MITRE·05:11 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-45722?

CVE-2026-45722 has a severity rating of high, with a score of 7.1.

2

What is the risk level associated with CVE-2026-45722?

CVE-2026-45722 has a risk level of 48.

3

How can I fix CVE-2026-45722?

To fix CVE-2026-45722, upgrade to Nextcloud Tables app version 0.9.7 or 1.0.2 or later.

4

What type of vulnerability is CVE-2026-45722?

CVE-2026-45722 is a SQL Injection vulnerability affecting the Tables app in Nextcloud.

5

Who is affected by CVE-2026-45722?

Users of Nextcloud Tables app versions 0.9.0 to before 0.9.7 and 1.0.0 to before 1.0.2 are affected by CVE-2026-45722.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
CVE-2026-45722 - Nextcloud: Tables app allows limited SQLi in ORDER BY with malicious sort order argument for Table Views - SecAlerts