Medium severity6.8NVD Advisory· Published Nov 2, 2020· Updated Jun 17, 2026
CVE-2020-8236
CVE-2020-8236
Description
A wrong configuration in Nextcloud Server 19.0.1 incorrectly made the user feel the passwordless WebAuthn is also a two factor verification by asking for the PIN of the passwordless WebAuthn but not verifying it.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: = 19.0.1
Patches
Vulnerability mechanics
References
2- hackerone.com/reports/924393nvdExploitThird Party Advisory
- nextcloud.com/security/advisory/nvdBroken LinkVendor Advisory
News mentions
0No linked articles in our index yet.