File Lock Manipulation Vulnerability in WebDAV Plugin by WordPress
CVE-2026-82980

6.3MEDIUM

Key Information:

Vendor

Nextcloud

Vendor
CVE Published:
18 September 2026

What is CVE-2026-82980?

This vulnerability allows any authenticated user to manipulate file locks of other users through absolute WebDAV paths. The plugin improperly resolves file paths without validating the authenticated session, enabling malicious users to lock files that do not belong to them. This can result in interrupted workflows by blocking write operations such as saving edits or uploading files. Additionally, the plugin allows unauthorized retrieval of lock tokens, which can be exploited to remove locks placed by legitimate users, further jeopardizing file integrity and collaborative efforts.

Affected Version(s)

Files Lock 31.0.0 <= 33.0.0

References

CVSS V3.0

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Balvant Chavda (0x0doteth)
.