← Vulnerability feed

Vulnerability record · CVE-2021-32726 · published 12 July 2021

CVE-2021-32726: Nextcloud server improper authentication vulnerability

Nextcloud · Nextcloud Server

Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, webauthn tokens were not deleted after a user has been deleted. If a victim reused an earlier used username, the previous user could gain access to their account. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds.

9.8 CVSS 3.1 Critical EPSS 1.8% · top 22.7% CWE-708 · CWE-708CWE-287 · Improper authentication
9.8CVSS 3.1 base score, v2 7.5
1.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, webauthn tokens were not deleted after a user has been deleted. If a victim reused an earlier used username, the previous user could gain access to their account. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-32726 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-49792Nextcloud server improper restriction of authentication attempts vulnerabilityNextcloud Server provides data storage for Nextcloud, an open source cloud platform. In Nextcloud Server prior to versions 26.0.9 and 27.1.4; as well…EPSS 1.0%9.8CVE-2023-48306Nextcloud server server-side request forgery (ssrf) vulnerabilityNextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.11, 26.0.6…EPSS 0.80%9.8CVE-2021-32802Nextcloud server inclusion from untrusted sphere vulnerabilityNextcloud server is an open source, self hosted personal cloud. Nextcloud supports rendering image previews for user provided file content. For some …EPSS 2.6%9.8CVE-2021-22915Nextcloud server improper restriction of authentication attempts vulnerabilityNextcloud server before 19.0.11, 20.0.10, 21.0.2 is vulnerable to brute force attacks due to lack of inclusion of IPv6 subnets in rate-limiting consi…EPSS 1.7%9.1CVE-2023-35172Nextcloud server improper restriction of authentication attempts vulnerabilityNextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform. In NextCloud Server version…EPSS 0.92%9.1CVE-2021-32654Nextcloud server insecure direct object reference vulnerabilityNextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.11, 20.0.10, and 21.0.2, an attacker is able to receive …EPSS 1.8%8.8CVE-2023-45151Nextcloud server cleartext storage of sensitive data vulnerabilityNextcloud server is an open source home cloud platform. Affected versions of Nextcloud stored OAuth2 tokens in plaintext which allows an attacker who…EPSS 0.48%8.8CVE-2023-35928Nextcloud server vulnerabilityNextcloud Server is a space for data storage on Nextcloud, a self-hosted productivity playform. In NextCloud Server versions 25.0.0 until 25.0.7 and …EPSS 0.98%

Source: NIST National Vulnerability Database (record CVE-2021-32726), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.