
Nextcloud, the Germany-based open-source file storage and collaboration platform, left an internal database publicly accessible, exposing 367,000 records that included employee information, client contracts, invoices and technical scripts used to deploy the company’s software on customer systems.
Researchers discovered the unsecured Elasticsearch cluster on May 18. The database held roughly 7.92 gigabytes of data across a single index tied to Nextcloud’s internal files. The most common file formats found in the exposed set were PDFs, numbering around 71,000, PNG images, numbering around 53,000, and markdown files, numbering around 23,000.
Nextcloud provides self-hosted alternatives to commercial cloud storage services such as Google Drive and Dropbox, allowing organizations to keep data on their own servers rather than a third party’s infrastructure. The platform has been positioned as a component of Euro-Office, a European-built alternative to Microsoft Office and Google Docs.
Much of the exposed material was stored without encryption. Invoices sent to and received by Nextcloud disclosed employee email addresses, client company names and addresses, and the contact information of individuals who submitted billing documents to the company. Contracts, templates and summary documents in the database outlined the scope of work, user bases and terms governing partnerships between Nextcloud and its clients.
Email domains tied to outside organizations turned up in the data, including those belonging to web hosting providers IONOS and STRATO, as well as German government bodies such as the Ministry of Schools and Education of the State of North Rhine-Westphalia.
The exposed files also contained shell and Python scripts written for clients to install and manage Nextcloud on their own systems. Some of those scripts included hardcoded database credentials. Unencrypted email files in the database carried message content, timestamps and sender and recipient addresses. Separate records listed the full names and work email addresses of people who had signed up for beta features and other Nextcloud integrations.
Additional data in the cluster included HTTP header information such as content type, length, language and timestamps; records showing which users had files shared with them, mostly identifying Nextcloud staff by first name alongside some external addresses; file paths, names and formats; and MD5 file hashes.
Nextcloud secured the database two days after being notified, and the dataset is no longer publicly accessible. There is no evidence that the exposed files were accessed by unauthorized parties before the cluster was closed.
A Nextcloud spokesperson said the exposure resulted from a misconfiguration in the company’s hosting infrastructure and was not connected to the Nextcloud software itself. The spokesperson said no customer-operated servers belonging to Nextcloud’s customers, partners or other users were affected by the incident. The company told Cybernews it investigated the matter immediately after being notified, resolved the exposure and reported it to the relevant state data protection officer, and said it was not aware of the leaked data being exploited.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543