CVE-2023-35928 is a critical vulnerability in Nextcloud Server and Nextcloud Enterprise Server versions 25.0.0-25.0.7 and 26.0.0-26.0.2 (and various older enterprise versions). It allows an authenticated user to access another user's login credentials and take over their account. This vulnerability carries a CVSS score of 8.8 (HIGH), indicating a network-based attack with low complexity, requiring only low privileges, and resulting in high confidentiality, integrity, and availability impacts. While no active exploitation or public exploit code has been identified, and community discussion is minimal, organizations should prioritize patching or implementing the provided workarounds due to the severe potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 19.0.0, < 19.0.13.9CPE matchmatch criteria | cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:* | ||
>= 20.0.0, < 20.0.14.14CPE matchmatch criteria | cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:* | ||
>= 21.0.0, < 21.0.9.12CPE matchmatch criteria | cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:* | ||
>= 22.0.0, < 22.2.10.12CPE matchmatch criteria | cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:* | ||
>= 23.0.0, < 23.0.12.7CPE matchmatch criteria | cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.