REVA is an interoperability platform. Prior to 2.42.3 and 2.40.3, a bug in the GRPC authorization middleware of the "Reva" component of OpenCloud allows a malicious user to bypass the scope verification of a public link. By exploiting this via the the "archiver" service this can be leveraged to create an archive (zip or tar-file) containing all resources that this creator of the public link has access to. This vulnerability is fixed in 2.42.3 and 2.40.3.
References
Configurations
Configuration 1 (hide)
|
History
24 Feb 2026, 20:57
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:heinlein:opencloud_reva:*:*:*:*:*:*:*:* | |
| First Time |
Heinlein
Heinlein opencloud Reva |
|
| References | () https://github.com/opencloud-eu/reva/commit/95aa2bc5d980eaf6cc134d75782b4f5ac7b36ae1 - Patch | |
| References | () https://github.com/opencloud-eu/reva/security/advisories/GHSA-9j2f-3rj3-wgpg - Vendor Advisory |
06 Feb 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-06 19:16
Updated : 2026-02-24 20:57
NVD link : CVE-2026-23989
Mitre link : CVE-2026-23989
CVE.ORG link : CVE-2026-23989
JSON object : View
Products Affected
heinlein
- opencloud_reva
CWE
CWE-863
Incorrect Authorization
