


Perceptive Security
SOC/SIEM Consultancy

Nextcloud is an open source content collaboration platform. From versions 0.7.0 to before 0.7.7, 0.8.0 to before 0.8.10, 0.9.0 to before 0.9.8, and 1.0.0 to bef…
Published:
31 mei 2026 om 22:00:00
Alert date:
1 juni 2026 om 20:04:42
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
A SQL injection vulnerability in Nextcloud's Tables app allows authenticated attackers to execute arbitrary SQL queries up to 20 bytes long through stored injection. The vulnerability affects multiple version ranges from 0.7.0 to 1.0.4 across different branches. Attackers can extract database information or modify data by crafting input that breaks out of length limitations. The issue has been patched in versions 0.7.7, 0.8.10, 0.9.8, 1.0.4, and 2.0.0.
Technical details
Mitigation steps:
Affected products:
Nextcloud
Nextcloud Tables
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-45545
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-x43f-gmgh-vvjj
https://github.com/nextcloud/tables/pull/2309
https://hackerone.com/reports/3462991
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
