CVE-2026-45722: Nextcloud: Tables app allows limited SQLi in ORDER BY with malicious sort order argument for Table Views
Nextcloud is an open source content collaboration platform. From versions 0.9.0 to before 0.9.7, and 1.0.0 to before 1.0.2, a missing sanitization in the Tables app allowed a user with access to the tables app to perform a limited SQL injection in the ORDER BY statement of a query. Compared to normal SQL injections, the ORDER BY is limited to extracting a single bit of information per request or to make the database wait for a given time. This issue has been patched in versions 0.9.7 and 1.0.2.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45722?
CVE-2026-45722 has a severity rating of high, with a score of 7.1.
What is the risk level associated with CVE-2026-45722?
CVE-2026-45722 has a risk level of 48.
How can I fix CVE-2026-45722?
To fix CVE-2026-45722, upgrade to Nextcloud Tables app version 0.9.7 or 1.0.2 or later.
What type of vulnerability is CVE-2026-45722?
CVE-2026-45722 is a SQL Injection vulnerability affecting the Tables app in Nextcloud.
Who is affected by CVE-2026-45722?
Users of Nextcloud Tables app versions 0.9.0 to before 0.9.7 and 1.0.0 to before 1.0.2 are affected by CVE-2026-45722.