CVE-2026-23989

REVA is an interoperability platform. Prior to 2.42.3 and 2.40.3, a bug in the GRPC authorization middleware of the "Reva" component of OpenCloud allows a malicious user to bypass the scope verification of a public link. By exploiting this via the the "archiver" service this can be leveraged to create an archive (zip or tar-file) containing all resources that this creator of the public link has access to. This vulnerability is fixed in 2.42.3 and 2.40.3.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:heinlein:opencloud_reva:*:*:*:*:*:*:*:*
cpe:2.3:a:heinlein:opencloud_reva:*:*:*:*:*:*:*:*

History

24 Feb 2026, 20:57

Type Values Removed Values Added
CPE cpe:2.3:a:heinlein:opencloud_reva:*:*:*:*:*:*:*:*
First Time Heinlein
Heinlein opencloud Reva
References () https://github.com/opencloud-eu/reva/commit/95aa2bc5d980eaf6cc134d75782b4f5ac7b36ae1 - () https://github.com/opencloud-eu/reva/commit/95aa2bc5d980eaf6cc134d75782b4f5ac7b36ae1 - Patch
References () https://github.com/opencloud-eu/reva/security/advisories/GHSA-9j2f-3rj3-wgpg - () https://github.com/opencloud-eu/reva/security/advisories/GHSA-9j2f-3rj3-wgpg - Vendor Advisory

06 Feb 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-06 19:16

Updated : 2026-02-24 20:57


NVD link : CVE-2026-23989

Mitre link : CVE-2026-23989

CVE.ORG link : CVE-2026-23989


JSON object : View

Products Affected

heinlein

  • opencloud_reva
CWE
CWE-863

Incorrect Authorization