Skip to content
Threat Feed
low advisory

Remote Code Execution Vulnerability in Nextcloud

A critical vulnerability in Nextcloud Hub, tracked as CVE-2024-28112, allows remote attackers to execute arbitrary code on the underlying application server.

CVE search metadata

CVE search record: CVE-2024-28112. Severity: medium. CVSS: 6.1. EPSS: 0.32%. KEV: no. Product: Nextcloud Hub (< 1.8.3). Brief: Remote Code Execution Vulnerability in Nextcloud. Brief link: https://feed.craftedsignal.io/briefs/2026-09-nextcloud-rce/

Nextcloud has released a security advisory addressing a remote code execution (RCE) vulnerability, identified as CVE-2024-28112. This flaw exists within the Nextcloud Hub software and stems from the improper handling of user-supplied input during request processing. An unauthenticated or remote attacker can leverage this vulnerability to inject and execute malicious code on the application server. This level of compromise grants the attacker the ability to read, modify, or delete sensitive data stored within the Nextcloud environment and potentially pivot into the wider network infrastructure. Given the critical nature of the vulnerability, organizations running Nextcloud Hub should prioritize patching their instances to the vendor-recommended version immediately.

Impact

Successful exploitation of CVE-2024-28112 allows an attacker to achieve full remote code execution on the server hosting Nextcloud. This provides the actor with unauthorized access to file stores, user credentials, and database contents, potentially leading to total system compromise and data exfiltration.

Recommendation

  • Identify all internet-facing Nextcloud Hub instances and audit logs for anomalous POST requests or unexpected child processes spawned by the web server user.
  • Apply the security update provided by Nextcloud to resolve CVE-2024-28112 immediately.
  • Review web server access logs for requests containing suspicious payload patterns that could indicate attempted exploitation of the input handling flaw.

Immediate actions

Patch Nextcloud Hub to 1.8.3 or later

IT Operations 24h

Mitigations

Upgrade Nextcloud Hub to 1.8.3 or later

immediate IT Operations

CVE-2024-28112