Vulnerability record · CVE-2023-32320 · published 22 June 2023
CVE-2023-32320: Nextcloud server improper restriction of authentication attempts vulnerability
Nextcloud · Nextcloud Server
Nextcloud Server is a data storage system for Nextcloud, a self-hosted productivity platform. When multiple requests are sent in parallel, all of them were executed even if the amount of faulty requests succeeded the limit by the time the response was sent to the client. This allowed someone to send as many requests the server could handle in parallel to bruteforce protected details instead of the configured limit, default 8. Nextcloud Server versions 25.0.7 and 26.0.2 and Nextcloud Enterprise Server versions 21.0.9.12, 22.2.10.12, 23.0.12.7, 24.0.12.2, 25.0.7 and 26.0.2 contain patches for this issue.
Description
Nextcloud Server is a data storage system for Nextcloud, a self-hosted productivity platform. When multiple requests are sent in parallel, all of them were executed even if the amount of faulty requests succeeded the limit by the time the response was sent to the client. This allowed someone to send as many requests the server could handle in parallel to bruteforce protected details instead of the configured limit, default 8. Nextcloud Server versions 25.0.7 and 26.0.2 and Nextcloud Enterprise Server versions 21.0.9.12, 22.2.10.12, 23.0.12.7, 24.0.12.2, 25.0.7 and 26.0.2 contain patches for this issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/nextcloud/security-advisories/security/advisories/GHSA-qphh-6xh7-vffg | PatchVendor Advisory |
| https://github.com/nextcloud/server/pull/38274 | Patch |
| https://hackerone.com/reports/1918525 | Permissions Required |
| https://github.com/nextcloud/security-advisories/security/advisories/GHSA-qphh-6xh7-vffg | PatchVendor Advisory |
| https://github.com/nextcloud/server/pull/38274 | Patch |
| https://hackerone.com/reports/1918525 | Permissions Required |
Track CVE-2023-32320 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-32320), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.