Impact
The Approval app’s approve/reject endpoint is designed to require the file’s current etag as a freshness check, blocking an approver from acting on a file that has changed since review. The backend only enforces this check when the etag parameter is present and non‑empty in the request. Because an attacker can intercept and modify the approval request to omit the etag field entirely, the freshness check is bypassed, allowing the attacker to approve or reject a file version they never reviewed. This flaw is a form of improper validation vulnerability classified as CWE‑840.
Affected Systems
The affected product is Nextcloud’s Approval app. No specific version information is provided by the CNA, so all installed instances of the Approval app that use the described endpoint are potentially impacted.
Risk and Exploitability
The CVSS score is 4.3, indicating a lower‑to‑moderate severity, and the EPSS score is less than 1 percent, suggesting a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, further implying that there are currently no known widespread attacks. The likely attack vector is interception or tampering of the approval request in transit, such as via a local network attacker or man‑in‑the‑middle. Because the flaw allows an attacker to perform an action that the user would have had to review, the impact could be significant for environments that rely heavily on the correctness of the approval process.
OpenCVE Enrichment