Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://hackerone.com/reports/3610332 |
|
Fri, 18 Sep 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nextcloud
Nextcloud approval |
|
| Vendors & Products |
Nextcloud
Nextcloud approval |
Fri, 18 Sep 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Approval app's approve/reject endpoint is meant to require the file's current etag as a freshness check, preventing an approver from approving or rejecting a file whose contents changed after they reviewed it. The backend only enforced this check when the etag parameter was present and non-empty in the request. An attacker able to intercept and modify the approval request could omit the etag field entirely, bypassing the freshness check and approving or rejecting a file version they never reviewed. | |
| Weaknesses | CWE-840 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2026-09-18T01:26:04.619Z
Reserved: 2026-08-31T15:00:00.543Z
Link: CVE-2026-82982
No data.
Status : Received
Published: 2026-09-18T02:17:08.030
Modified: 2026-09-18T02:17:08.030
Link: CVE-2026-82982
No data.
OpenCVE Enrichment
Updated: 2026-09-18T11:00:08Z