File owners cannot unlock TYPE_TOKEN locks, causing permanent inaccessibility
CVE-2026-77165 Published on September 21, 2026

File owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no recovery path outside of the database.

NVD

Weakness Type

What is an Authorization Vulnerability?

The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CVE-2026-77165 has been classified to as an Authorization vulnerability or weakness.


Products Associated with CVE-2026-77165

Want to know whenever a new CVE is published for Nextcloud Server? stack.watch will email you.

 

Affected Versions

Nextcloud Server: