File owners cannot unlock TYPE_TOKEN locks, causing permanent inaccessibility
CVE-2026-77165 Published on September 21, 2026
File owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no recovery path outside of the database.
Weakness Type
What is an Authorization Vulnerability?
The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVE-2026-77165 has been classified to as an Authorization vulnerability or weakness.
Products Associated with CVE-2026-77165
Want to know whenever a new CVE is published for Nextcloud Server? stack.watch will email you.
Affected Versions
Nextcloud Server:- Version 32.0.0, <= 34.0.0 is affected.