CVE-2026-23989

REVA is an interoperability platform. Prior to 2.42.3 and 2.40.3, a bug in the GRPC authorization middleware of the "Reva" component of OpenCloud allows a malicious user to bypass the scope verification of a public link. By exploiting this via the the "archiver" service this can be leveraged to create an archive (zip or tar-file) containing all resources that this creator of the public link has access to. This vulnerability is fixed in 2.42.3 and 2.40.3.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:heinlein:opencloud_reva:*:*:*:*:*:*:*:*
cpe:2.3:a:heinlein:opencloud_reva:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:22

Type Values Removed Values Added
Summary
  • (es) REVA es una plataforma de interoperabilidad. Antes de las versiones 2.42.3 y 2.40.3, un error en el middleware de autorización GRPC del componente 'Reva' de OpenCloud permite a un usuario malintencionado eludir la verificación de alcance de un enlace público. Al explotar esto a través del servicio 'archiver', se puede aprovechar para crear un archivo (zip o tar) que contenga todos los recursos a los que tiene acceso el creador de dicho enlace público. Esta vulnerabilidad está corregida en las versiones 2.42.3 y 2.40.3.

24 Feb 2026, 20:57

Type Values Removed Values Added
CPE cpe:2.3:a:heinlein:opencloud_reva:*:*:*:*:*:*:*:*
First Time Heinlein
Heinlein opencloud Reva
References () https://github.com/opencloud-eu/reva/commit/95aa2bc5d980eaf6cc134d75782b4f5ac7b36ae1 - () https://github.com/opencloud-eu/reva/commit/95aa2bc5d980eaf6cc134d75782b4f5ac7b36ae1 - Patch
References () https://github.com/opencloud-eu/reva/security/advisories/GHSA-9j2f-3rj3-wgpg - () https://github.com/opencloud-eu/reva/security/advisories/GHSA-9j2f-3rj3-wgpg - Vendor Advisory

06 Feb 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-06 19:16

Updated : 2026-06-17 10:22


NVD link : CVE-2026-23989

Mitre link : CVE-2026-23989

CVE.ORG link : CVE-2026-23989


JSON object : View

Products Affected

heinlein

  • opencloud_reva
CWE
CWE-863

Incorrect Authorization