The Nextcloud Approval app allows approval or disapproval of files in the sidebar. Prior to 1.3.1 and 2.5.0, an authenticated user listed as a requester in a workflow can set another user’s file into the “pending approval” without access to the file by using the numeric file id. This vulnerability is fixed in 1.3.1 and 2.5.0.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 05 Dec 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 05 Dec 2025 17:45:00 +0000

Type Values Removed Values Added
Description The Nextcloud Approval app allows approval or disapproval of files in the sidebar. Prior to 1.3.1 and 2.5.0, an authenticated user listed as a requester in a workflow can set another user’s file into the “pending approval” without access to the file by using the numeric file id. This vulnerability is fixed in 1.3.1 and 2.5.0.
Title Nextcloud Approval app allows users to request approval for other users file
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-12-05T18:10:00.615Z

Reserved: 2025-12-03T15:28:02.992Z

Link: CVE-2025-66515

cve-icon Vulnrichment

Updated: 2025-12-05T18:09:54.033Z

cve-icon NVD

Status : Received

Published: 2025-12-05T18:15:57.623

Modified: 2025-12-05T18:15:57.623

Link: CVE-2025-66515

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses