CVE-2026-45266
Nextcloud is an open source content collaboration platform. Prior to versions 21.1.10, 22.0.11, and 23.0.3, a low-privileged user can force
CVSS
3.5
Bajo
EPSS
0.2%
p10
KEV
—
Exploit Today
3
0-100
Publicado: 1 jun 2026 · Última mod.: 22 jul 2026 · CWE-284
0.2%EPSS · 30 días0.2%
2026-07-152026-08-12
Nextcloud is an open source content collaboration platform. Prior to versions 21.1.10, 22.0.11, and 23.0.3, a low-privileged user can force other user's microphones to be muted in calls when no High-performance Backend is installed. This issue has been patched in versions 21.1.10, 22.0.11, and 23.0.3.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-595058.6 ALT—
——0CWE-284: Improper Access Control5hCVE-2026-595018.2 ALT—
——0CWE-284: Improper Access Control5hCVE-2026-133677.8 ALT—
——0IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation vulnerability in the oninit setuid-root utility.18hCVE-2026-599177.8 ALT—
——0Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.10hCVE-2026-599147.8 ALT—
——0Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.10hCVE-2026-67287——
——0Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated attacker can create comments on instances with disabled guest commenting by overriding the setting in question with user supplied input.1d