Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-77169

Quick assessment

Affected
Nextcloud Team Folders
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在“团队文件夹”(原“群文件夹”)应用与“工作区”应用配合使用时存在一个漏洞,该漏洞允许仅通过 API/REST 的委派管理员绕过文件夹级别的授权控制。工作区应用允许组织通过 API/REST 委派有限的团队文件夹管理权限,并限制管理员只能访问其拥有高级权限的文件夹。

AI Predicted 6.5 Difficulty: Moderate
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-77169

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed API/REST-only delegated administrators to bypass folder-level authorization controls. The workspace app enables organizations to delegate limited administrative privileges for team folder management via API/REST only, restricting access to folders for which the admin has advanced permissions.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
访问控制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Nextcloud Team Folders 13.0.0 ~ 22.0.0 -

II. Public POCs for CVE-2026-77169

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-77169

登录查看更多情报信息。

Other References for CVE-2026-77169 (1)

Same Patch Batch · Nextcloud · 2026-09-18 · 7 CVEs total

CVE-2026-77170 Deck配置API越权设置任意看板配置漏洞
CVE-2026-77164 Nextcloud Circles盲SSRF漏洞
CVE-2026-82982 CVE-2026-82982
CVE-2026-82980 CVE-2026-82980
CVE-2026-82985 CVE-2026-82985
CVE-2026-68493 CVE-2026-68493

IV. Related Vulnerabilities

V. Comments for CVE-2026-77169

No comments yet


Leave a comment