Impact
File owners are unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no recovery path outside of the database. This prevents access to, modification of, or deletion of affected files, disrupting normal operation and potentially resulting in data inaccessibility. The weakness is a lack of proper access control. If an attacker or an authorized user places a lock, the victim cannot ever unlock it, effectively creating a denial‑of‑service condition that can accumulate over time.
Affected Systems
Nextcloud Server is the affected product. No specific version information is available in the entry.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector requires an authenticated user able to place TYPE_TOKEN locks; the lack of a recovery path means that any user who can create such a lock can cause irreversible file locking for a victim. The overall exploitability is moderate, as an attacker must gain enough access to place the lock, but the impact to availability is significant once a lock is in place.
OpenCVE Enrichment