CVE-2026-45156 is an authentication bypass vulnerability in Nextcloud's User OIDC application affecting versions 0.3.0 to before 3.1.0, 5.0.0 to before 5.1.0, and 6.0.0 to before 6.4.0. The flaw is caused by missing JWT signature verification in the ID4me authentication flow. In the vulnerable implementation, identity claims from the token were processed without cryptographically validating that the token had been signed by a trusted authority. As a result, a malicious or compromised ID4me Identity Authority could forge authentication tokens containing arbitrary user identifiers and cause a vulnerable Nextcloud instance to accept them as valid. This could allow impersonation of any existing user, including administrators, when the ID4me federated identity feature is enabled.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small, focused exploit PoC consisting of a README and one Python script, nextcloud_id4me_poc.py. The script targets CVE-2026-45156 in Nextcloud's user_oidc ID4me flow, where JWT payloads are allegedly processed without cryptographic signature verification. The exploit’s core capability is forging an unsigned JWT using alg:none with attacker-controlled identity claims, especially sub/preferred_username, to impersonate an arbitrary account such as admin. The Python script is structured as an end-to-end automation tool rather than a minimal PoC. It includes console/banner helpers, a JWT forging routine, a fake local OIDC/ID4me HTTP server implemented with Python’s http.server, shared state for coordinating the flow, target detection logic, CSRF token extraction, ID4me detection, ngrok tunnel setup via pyngrok, exploit triggering, and final reporting. The main() function parses a target URL plus optional --user and --port arguments, then instantiates a NextcloudExploit object and runs the full workflow. Operationally, the exploit appears designed to: detect whether the target is a Nextcloud instance, gather CSRF/session material, verify presence of the user_oidc/ID4me functionality, generate a forged unsigned JWT, expose a local fake identity provider through ngrok, and drive the target through the ID4me authentication flow so the vulnerable server accepts the forged token and logs the attacker in as the chosen user. This makes it a real exploit rather than a detector, but it is still best classified as OPERATIONAL rather than framework-weaponized because the payload is a hardcoded forged token flow rather than a reusable exploit framework module. Fingerprintable observables are limited but useful: the script references the vulnerable target file lib/Controller/Id4meController.php, the user_oidc path /apps/user_oidc/, a default forged issuer of https://attacker.id4me, ngrok setup infrastructure, example target URLs, and a default local listener port of 9999. The README mainly documents the vulnerability, setup, usage, and reconnaissance hints, while the Python file contains the actual exploit logic.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.