Nextcloud · Team Folders · CVE-2026-77169
**Name of the Vulnerable Software and Affected Versions**
Nextcloud Team Folders (affected versions not specified)
**Description**
An issue exists in the team folders app (previously known as group folders) when integrated with the workspace app. This flaw allows delegated administrators with API/REST-only privileges to bypass authorization controls at the folder level. The workspace app is designed to delegate limited administrative rights for team folder management exclusively via API/REST, which should restrict access to folders where the administrator possesses advanced permissions.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.