Description
The Approval app's approve/reject endpoint is meant to require the file's current etag as a freshness check, preventing an approver from approving or rejecting a file whose contents changed after they reviewed it. The backend only enforced this check when the etag parameter was present and non-empty in the request. An attacker able to intercept and modify the approval request could omit the etag field entirely, bypassing the freshness check and approving or rejecting a file version they never reviewed.
Published: 2026-09-18
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Approval Bypass
Action: Immediate Patch
AI Analysis

Impact

The Approval app’s approve/reject endpoint is designed to require the file’s current etag as a freshness check, blocking an approver from acting on a file that has changed since review. The backend only enforces this check when the etag parameter is present and non‑empty in the request. Because an attacker can intercept and modify the approval request to omit the etag field entirely, the freshness check is bypassed, allowing the attacker to approve or reject a file version they never reviewed. This flaw is a form of improper validation vulnerability classified as CWE‑840.

Affected Systems

The affected product is Nextcloud’s Approval app. No specific version information is provided by the CNA, so all installed instances of the Approval app that use the described endpoint are potentially impacted.

Risk and Exploitability

The CVSS score is 4.3, indicating a lower‑to‑moderate severity, and the EPSS score is less than 1 percent, suggesting a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, further implying that there are currently no known widespread attacks. The likely attack vector is interception or tampering of the approval request in transit, such as via a local network attacker or man‑in‑the‑middle. Because the flaw allows an attacker to perform an action that the user would have had to review, the impact could be significant for environments that rely heavily on the correctness of the approval process.

Generated by OpenCVE AI on September 19, 2026 at 21:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest official patch for the Nextcloud Approval app or upgrade to a version that enforces the etag check regardless of whether the parameter is present.
  • Configure the server to enforce strict transport security and utilize HTTPS with valid certificates to prevent request interception or modification.
  • Modify the backend logic to require the etag header for all approve/reject requests, returning an error if it is missing or empty.

Generated by OpenCVE AI on September 19, 2026 at 21:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Sat, 19 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Approval Endpoint Bypass via Omitted ETag

Sat, 19 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Title Approval Endpoint Bypass via Omitted ETag

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Nextcloud
Nextcloud approval
Vendors & Products Nextcloud
Nextcloud approval

Fri, 18 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Description The Approval app's approve/reject endpoint is meant to require the file's current etag as a freshness check, preventing an approver from approving or rejecting a file whose contents changed after they reviewed it. The backend only enforced this check when the etag parameter was present and non-empty in the request. An attacker able to intercept and modify the approval request could omit the etag field entirely, bypassing the freshness check and approving or rejecting a file version they never reviewed.
Weaknesses CWE-840
References
Metrics cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Nextcloud Approval
cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-09-18T19:42:03.054Z

Reserved: 2026-08-31T15:00:00.543Z

Link: CVE-2026-82982

cve-icon Vulnrichment

Updated: 2026-09-18T19:41:57.871Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T02:17:08.030

Modified: 2026-09-18T20:17:25.790

Link: CVE-2026-82982

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T21:45:16Z

Weaknesses