6.5
CVE-2026-45275
- EPSS 0.36%
- Veröffentlicht 01.06.2026 16:51:22
- Zuletzt bearbeitet 22.07.2026 07:10:00
- CVE-Watchlists
- Unerledigt
Nextcloud: Authorization bypass in approval feature allows unauthorized file sharing with approvers
Authorization bypass in approval feature allows unauthorized file sharing with approvers
Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, a privilege escalation vulnerability exists in the Approval app that allows a user without sharing permissions to force the system to share a file with approvers. This results in an authorization bypass and privilege escalation, allowing unauthorized distribution of restricted files. This issue has been patched in version 2.7.2.
Mögliche Gegenmaßnahme
Approval: * Disable the Approval app
* No other workaround available
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.36% | 0.275 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-285 Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
https://github.com/nextcloud/approval/pull/392
https://hackerone.com/reports/3593780
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-v8q8-w6c3-3gv9
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-v8q8-w6c3-3gv9