The essentials
- On 9 October 2026, CERT-FR issued advisory CERTFR-2026-AVI-1283 covering five Nextcloud security bulletins dated 8 October (GHSA), with risks including confidentiality impact, policy bypass, remote denial of service, and privilege escalation.
- Affected scope includes Nextcloud Server (32.0.x, 33.0.x, 34.0.x branches), the files_lock app, Collectives, and multiple Team Folders release lines; patched version thresholds are listed in the official advisory.
- CERT-FR points operators to vendor bulletins for fixes; one advisory (GHSA-22w9-gpgv-pcgc) describes TYPE_TOKEN locks that can leave files stuck for the owner until database-level recovery.
What CERT-FR reports
On 9 October 2026, France’s CERT-FR published advisory CERTFR-2026-AVI-1283 on multiple vulnerabilities in the Nextcloud stack. It references five vendor bulletins released on 8 October 2026 (GHSA identifiers). The official summary highlights privilege escalation, remote denial of service, data confidentiality impact, and security-policy bypass.
Scope goes beyond core Server: the advisory also lists Collectives, the files_lock extension, and many Team Folders branches, each with different fixed-version thresholds. For every component, CERT-FR names versions below a stated floor — the full matrix is in the online advisory.
Server and apps: match version thresholds
For Nextcloud Server, the advisory cites branches such as 32.0.x before 32.0.12, 33.0.x before 33.0.6, and 34.0.x before 34.0.1. Collectives should be at least 4.4.1. files_lock on 33.0.x needs 33.0.6 or newer. Team Folders spans major versions 13 through 22 with distinct fixes — a up-to-date Server paired with a forgotten group-folders app can still be exposed.
- Inventory Server, third-party Nextcloud apps, and versions shown in the admin UI.
- Compare each component to the advisory’s “Affected systems” table before closing a patch ticket.
- Schedule maintenance: some issues touch file sharing and locking — users may see impact during app upgrades or restarts.
Concrete case: file locks (GHSA-22w9-gpgv-pcgc)
One 8 October bulletin, GHSA-22w9-gpgv-pcgc, affects locking: a collaborator with write share access could set a TYPE_TOKEN lock that the file owner could not remove, leaving the file stuck with no in-app recovery — the vendor notes removing the lock in the database as a workaround. Patched Server versions announced by Nextcloud include 32.0.6, 33.0.6, and 34.0.1 (by branch). Vendor severity: moderate (CVSS 3.1 score 6.5).
Teams running self-hosted Nextcloud
Nextcloud is often deployed on-prem or with a European host for document sharing, project spaces, or as an alternative to hyperscaler sync. Lagging patches on an LTS branch (32.x) or an unmaintained app repeats a familiar collaboration pattern: the core is current, but an extension keeps attack surface open. The CERT-FR notice does not replace Nextcloud release notes — use those for `occ` upgrade steps and Server → apps ordering.
Sources
This note was drafted with AI tools from the cited sources, then reviewed and published under the responsibility of Jordan FOUASSIER, publication director. We summarise the facts and add our reading; source text and images are not reproduced. An error? Write to contact@aigyrosgroup.com.