← Back to CVE List

CVE-2021-32726

Published: 2021-07-12T20:15Z
Last Modified: 2024-11-21T06:07Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, webauthn tokens were not deleted after a user has been deleted. If a victim reused an earlier used username, the previous user could gain access to their account. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt