← Vulnerability feed

Vulnerability record · CVE-2026-45545 · published 1 June 2026

CVE-2026-45545: Nextcloud tables sql injection vulnerability

Nextcloud · Tables

Nextcloud is an open source content collaboration platform. From versions 0.7.0 to before 0.7.7, 0.8.0 to before 0.8.10, 0.9.0 to before 0.9.8, and 1.0.0 to before 1.0.4, an authenticated attacker with access to the Tables app may be able to execute arbitrary up to 20 bytes long SQL queries, through a stored injection. With carefully crafted input it is possible to break out of the length limitation. The attacker could use this to extract information from the database, or modify data. This issue has been patched in versions 0.7.7, 0.8.10, 0.9.8, 1.0.4, and 2.0.0.

8.2 CVSS 3.1 High EPSS 0.52% · top 58.3% CWE-89 · SQL injection
8.2CVSS 3.1 base score
0.52%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
22 Jul 2026Last modified by NVD

Description

Nextcloud is an open source content collaboration platform. From versions 0.7.0 to before 0.7.7, 0.8.0 to before 0.8.10, 0.9.0 to before 0.9.8, and 1.0.0 to before 1.0.4, an authenticated attacker with access to the Tables app may be able to execute arbitrary up to 20 bytes long SQL queries, through a stored injection. With carefully crafted input it is possible to break out of the length limitation. The attacker could use this to extract information from the database, or modify data. This issue has been patched in versions 0.7.7, 0.8.10, 0.9.8, 1.0.4, and 2.0.0.

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-45545 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.1CVE-2026-45722Nextcloud tables sql injection vulnerabilityNextcloud is an open source content collaboration platform. From versions 0.9.0 to before 0.9.7, and 1.0.0 to before 1.0.2, a missing sanitization in…EPSS 0.49%6.5CVE-2024-52511Nextcloud tables insecure direct object reference vulnerabilityNextcloud Tables allows users to to create tables with individual columns. By directly specifying the ID of a table or view, a malicious user could b…EPSS 0.46%5.3CVE-2025-66513Nextcloud tables insecure direct object reference vulnerabilityNextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.9, 0.9.6, and 1.0.1, the information which table (numeric…EPSS 0.30%4.3CVE-2026-45544Nextcloud tables vulnerabilityNextcloud is an open source content collaboration platform. From version 0.8.0 to before version 1.0.4, the view filter criteria is exposed to users …EPSS 0.37%4.3CVE-2025-66551Nextcloud tables insecure direct object reference vulnerabilityNextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.6 and 0.9.3, a malicious user was able to create their ow…EPSS 0.25%4.3CVE-2025-66553Nextcloud tables insecure direct object reference vulnerabilityNextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.7 and 0.9.4, authenticated users were able to view meta d…EPSS 0.28%4.3CVE-2024-52507Nextcloud tables insecure direct object reference vulnerabilityNextcloud Tables allows users to to create tables with individual columns. The information which Table (numeric ID) is shared with which groups and u…EPSS 0.42%9.8CVE-2026-76461Cisco AsyncOS email parsing SQL injection allows root command executionCisco AsyncOS Software for Cisco Secure Email Gateway fails to properly validate email parsing input, allowing crafted email messages containing mali…KEVEPSS 28%analysed

Source: NIST National Vulnerability Database (record CVE-2026-45545), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.