Nextcloud left an internal Elasticsearch database publicly accessible, exposing about 367,000 records and roughly 7.92 GB of data that included invoices, client contracts, employee information, internal documents, unencrypted email files, beta tester lists, file-sharing metadata, and deployment scripts. Some of the exposed shell and Python scripts reportedly contained hardcoded database credentials, increasing the risk of follow-on compromise, while referenced external domains included providers such as IONOS and STRATO as well as German government entities including MSB NRW.
The database was discovered on May 18 and secured on May 27, two days after notification, according to reporting cited by Cybernews and others. Nextcloud said the exposure resulted from a hosting infrastructure misconfiguration rather than a flaw in its product, stated that no customer-operated servers were affected, and said it had no evidence of unauthorized access or exploitation before the database was locked down; the company also reported the incident to the relevant state data protection officer.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Following the exposure, Nextcloud reported the matter to the relevant state data protection officer. The company also stated that no customer-operated servers were affected and that it had no evidence of unauthorized access before the database was closed.
Nextcloud reportedly secured the exposed Elasticsearch database on 2026-05-27, two days after being notified. The company said the exposure was caused by a hosting infrastructure misconfiguration rather than a flaw in Nextcloud software.
Cybernews reportedly found a publicly accessible Elasticsearch cluster belonging to Nextcloud on 2026-05-18. The database contained about 7.92 GB of data across roughly 367,000 records, including invoices, contracts, internal documents, emails, and scripts with hardcoded database credentials.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecyberveille.ch
Open sourceteiss.co.uk
Open sourcecybernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.