Skip to content

Nextcloud Data Breach: 8 GB Exposed via Unsecured Elasticsearch Cluster

In a nutshell: Nextcloud internal data such as contracts and integration scripts were made publicly accessible through an unsecured Elasticsearch cluster.

An unprotected Elasticsearch cluster disclosed sensitive internal Nextcloud data. Affected items include contracts and integration scripts.

An openly accessible Elasticsearch cluster exposed approximately 8 GB of internal Nextcloud data. The exposed data volume included contracts, integration scripts, and further sensitive company information.

For CISOs and information security officers, this incident presents several immediate risks: leaked contracts allow attackers and competing parties insight into business relationships and technical dependencies. Integration scripts can serve as a basis for targeted attacks on connected systems. Additionally, there is elevated phishing and social engineering risk, as attackers now have access to contact information and possibly organizational structures.

As countermeasures, the following should be reviewed: how long the cluster was exposed, which systems and services are affected based on the leaked integration scripts, and whether customers and employees were subject to targeted phishing attempts. Furthermore, an audit of the company’s own Elasticsearch deployments for inadequate access control mechanisms is required.


Source: www.security-insider.de · Published 16 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: