Nextcloud · Nextcloud Enterprise Server · CVE-2026-45690
**Name of the Vulnerable Software and Affected Versions**
Nextcloud Server versions 32.0.0 through 32.0.8
Nextcloud Server versions 33.0.0 through 33.0.2
Nextcloud Enterprise Server (affected versions not specified)
**Description**
An authentication bypass allows attackers who possess a user's password to circumvent two-factor authentication (2FA) protections. During the login process for a 2FA-enabled account, the system generates a temporary session token before the second factor challenge is enforced. This token can be extracted and replayed using HTTP Basic Authentication to gain unauthorized access to authenticated endpoints.
**Recommendations**
Upgrade Nextcloud Server versions 32.0.0 through 32.0.8 to 32.0.9.
Upgrade Nextcloud Server versions 33.0.0 through 33.0.2 to 33.0.3.
Upgrade Nextcloud Enterprise Server to 33.0.3, 32.0.9, 31.0.14.5, 30.0.17.9, or 29.0.16.16.