The Nextcloud Approval app allows approval or disapproval of files in the sidebar. Prior to 1.3.1 and 2.5.0, an authenticated user listed as a requester in a workflow can set another user’s file into the “pending approval” without access to the file by using the numeric file id. This vulnerability is fixed in 1.3.1 and 2.5.0.
References
| Link | Resource |
|---|---|
| https://github.com/nextcloud/approval/commit/e30b56b7832255311ac800b7875f44866e88fff4 | Patch |
| https://github.com/nextcloud/approval/pull/334 | Issue Tracking |
| https://github.com/nextcloud/security-advisories/security/advisories/GHSA-q26g-fmjq-x5g5 | Patch Vendor Advisory |
| https://hackerone.com/reports/3338748 | Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
09 Dec 2025, 17:22
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/nextcloud/approval/commit/e30b56b7832255311ac800b7875f44866e88fff4 - Patch | |
| References | () https://github.com/nextcloud/approval/pull/334 - Issue Tracking | |
| References | () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-q26g-fmjq-x5g5 - Patch, Vendor Advisory | |
| References | () https://hackerone.com/reports/3338748 - Issue Tracking, Vendor Advisory | |
| CPE | cpe:2.3:a:nextcloud:approval:*:*:*:*:*:nextcloud:*:* | |
| First Time |
Nextcloud
Nextcloud approval |
05 Dec 2025, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-05 18:15
Updated : 2025-12-09 17:22
NVD link : CVE-2025-66515
Mitre link : CVE-2025-66515
CVE.ORG link : CVE-2025-66515
JSON object : View
Products Affected
nextcloud
- approval
CWE
CWE-287
Improper Authentication
