Filtered by vendor Nextcloud Subscriptions
Filtered by product Approval Subscriptions
Total 3 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2026-45275 1 Nextcloud 1 Approval 2026-06-03 6.5 Medium
Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, a privilege escalation vulnerability exists in the Approval app that allows a user without sharing permissions to force the system to share a file with approvers. This results in an authorization bypass and privilege escalation, allowing unauthorized distribution of restricted files. This issue has been patched in version 2.7.2.
CVE-2026-45277 1 Nextcloud 1 Approval 2026-06-03 3.3 Low
Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, authenticated users can check if arbitrary files are associated with specific approval workflows where they can request approval. This issue has been patched in version 2.7.2.
CVE-2025-66515 1 Nextcloud 1 Approval 2025-12-09 2.7 Low
The Nextcloud Approval app allows approval or disapproval of files in the sidebar. Prior to 1.3.1 and 2.5.0, an authenticated user listed as a requester in a workflow can set another user’s file into the “pending approval” without access to the file by using the numeric file id. This vulnerability is fixed in 1.3.1 and 2.5.0.