Impact
Any authenticated user can lock or unlock files that belong to other users by specifying absolute WebDAV paths. The DAV plugin resolves files directly from the request URI without verifying ownership, allowing attackers to impose a write lock that blocks standard operations such as PUT, MOVE, DELETE or editor saves. In addition, the application returns the lock token to unauthorized callers, enabling them to remove token‑based locks of other users. This flaw is an authentication bypass (CWE‑287) that results in a denial of file operations for targeted users and the potential leakage of lock tokens.
Affected Systems
The vulnerability resides in the Nextcloud Files Lock component, specifically the default DAV plugin. All installations that expose the WebDAV interface and allow authenticated users to target arbitrary absolute paths may be affected. Until a vendor update is applied, any current Nextcloud release using the default DAV plugin could be vulnerable.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity. The EPSS score of <1% suggests a low likelihood of widespread exploitation at present, and the vulnerability is not listed in CISA's KEV catalog. The attack requires only local authentication; once a user account is compromised or credentials are obtained, an attacker can lock or unlock other users' files and disclose lock tokens. The impact includes unilateral denial of file operations for targeted users and potential lock‑token leakage, which could be leveraged to remove or manipulate other users’ locks.
OpenCVE Enrichment