{"id":"CVE-2026-45153","summary":"Nextcloud: PIN bypass in PassCodeActivity via back button","details":"Nextcloud is an open source content collaboration platform. From version 33.0.0 to before version 33.1.0, after unlocking a locked Android phone the back-button could be used to bypass the Nextcloud Files app PIN. This issue has been patched in version 33.1.0.","aliases":["BIT-nextcloud-2026-45153","GHSA-2w7v-5299-3hw5"],"modified":"2026-08-12T03:51:39.631451624Z","published":"2026-06-01T16:37:12.319Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-287"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45153.json"},"references":[{"type":"WEB","url":"https://hackerone.com/reports/3625210"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45153.json"},{"type":"ADVISORY","url":"https://github.com/nextcloud/security-advisories/security/advisories/GHSA-2w7v-5299-3hw5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45153"},{"type":"FIX","url":"https://github.com/nextcloud/android/pull/16896"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nextcloud/android","events":[{"introduced":"be604e5927095d3a14b2120ffbae5c1b1511d057"},{"fixed":"0c7b14c7e4b189c8c48bbaeb6470686dd92476b4"}],"database_specific":{"extracted_events":[{"introduced":"33.0.0"},{"fixed":"33.1.0"},{"introduced":"0"}],"source":["AFFECTED_FIELD","DESCRIPTION"]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45153.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N"}]}