Security Advisory

Back to advisories

Permission increase on re-sharing via OCS API (NC-SA-2017-001)

5th February 2017

Risk level: Medium

CVSS v3 Base Score: 5.4 (AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)

CWE: Permission Issues (CWE-275)

HackerOne report: 169680


A permission related issue within the OCS sharing API allowed an authenticated adversary to reshare shared files with an increasing permission set. This may allow an attacker to edit files in a share despite having only a 'read' permission set.Note that this only affects folders and files that the adversary has at least read-only permissions for.

Affected Software

  • Nextcloud Server < 10.0.2 (CVE-2017-0883)
  • Nextcloud Server < 9.0.55 (CVE-2017-0883)

Action Taken

The permissions are now properly checked on the OCS endpoint.


It is recommended that all instances are upgraded to Nextcloud 9.0.55 or 10.0.2.


The Nextcloud team thanks the following people for their research and responsible disclosure of the above advisory:

This advisory is licensed CC BY-SA 4.0.

You have javascript disabled. We tried to make sure the basics of our website work but some functionality will be missing.

This website is using cookies. By visiting you agree with our privacy policy. That's Fine