


Perceptive Security
SOC/SIEM Consultancy

Nextcloud is an open source content collaboration platform. From versions 0.9.0 to before 0.9.7, and 1.0.0 to before 1.0.2, a missing sanitization in the Tables…
Published:
31 May 2026 at 22:00:00
Alert date:
1 June 2026 at 20:04:42
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
Nextcloud's Tables app contains a SQL injection vulnerability affecting versions 0.9.0 to before 0.9.7 and 1.0.0 to before 1.0.2. The vulnerability allows authenticated users with access to the Tables app to perform limited SQL injection attacks through the ORDER BY statement of queries. While limited in scope compared to typical SQL injections, attackers can extract data one bit at a time or cause database delays. The issue stems from missing input sanitization and has been patched in versions 0.9.7 and 1.0.2.
Technical details
Mitigation steps:
Affected products:
Nextcloud Tables
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-45722
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-5h2w-c7px-hp4j
https://github.com/nextcloud/tables/pull/2186
https://hackerone.com/reports/3446689
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
