Vulnérabilité dans Nextcloud Server (17 septembre 2026)
A critical vulnerability has been identified in Nextcloud Server, allowing for remote code execution. Versions prior to 22.2.10.42, 23.0.12.38, 24.0.13.37, 25.0.13.32, 26.0.13.29, 27.1.11.29, 28.0.14.20, 29.0.16.19, 30.0.17.12, 31.0.14.8, 32.0.13, 33.0.7, and 34.0.2 are all affected, presenting a significant risk of compromise.
A critical vulnerability has been discovered within Nextcloud Server. This vulnerability enables an attacker to execute arbitrary code remotely. The affected versions of Nextcloud Server are: Server versions 22.x prior to 22.2.10.42, Server versions 23.0.x prior to 23.0.12.38, Server versions 24.0.x prior to 24.0.13.37, Server versions 25.0.x prior to 25.0.13.32, Server versions 26.0.x prior to 26.0.13.29, Server versions 27.x and prior to 27.1.11.29, Server versions 28.0.x prior to 28.0.14.20, Server versions 29.0.x prior to 29.0.16.19, Server versions 30.0.x prior to 30.0.17.12, Server versions 31.0.x prior to 31.0.14.8, Server versions 32.0.x prior to 32.0.13, Server versions 33.0.x prior to 33.0.7, and Server versions 34.0.x prior to 34.0.2. The bulletin de sécurité Nextcloud GHSA-7hwf-8pcj-33h4 from September 17, 2026, is available at https://github.com/nextcloud/security-advisories/security/advisories/GHSA-7hwf-8pcj-33h4. Users are advised to refer to this bulletin for details on how to obtain and apply the necessary security patches.