CVE-2026-77169

Summary

A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed API/REST-only delegated administrators to bypass folder-level authorization controls. The workspace app enables organizations to delegate limited administrative privileges for team folder management via API/REST only, restricting access to folders for which the admin has advanced permissions.

Affected Software

VendorProductVersion RangeStatus
NextcloudTeam Folders13.0.0 < 22.0.0affected

Weaknesses

  • CWE-284: CWE-284 Improper Access Control - Generic

References