Vulnerability CVE-2022-29160


Published: 2022-05-20

Description:
Nextcloud Android is the Android client for Nextcloud, a self-hosted productivity platform. Prior to version 3.19.0, sensitive tokens, images, and user related details exist after deletion of a user account. This could result in misuse of the former account holder's information. Nextcloud Android version 3.19.0 contains a patch for this issue. There are no known workarounds available.

Type:

CWE-284

(Improper Access Control)

 References:
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-xcj9-3jch-qr2r
https://github.com/nextcloud/android/pull/9644
https://hackerone.com/reports/1222873

Copyright 2026, cxsecurity.com

 

Back to Top