Bypass Vulnerability in Approval App by Vendor
CVE-2026-82982

4.3MEDIUM

Key Information:

Vendor

Nextcloud

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-82982?

The Approval app contains a vulnerability in its approve/reject endpoint, which is designed to ensure the integrity of file approvals by requiring a valid etag as a freshness check. However, this check is only enforced if the etag parameter is included and populated in the request. An attacker who can intercept and alter the approval request may bypass this freshness check entirely by omitting the etag parameter, allowing them to approve or reject file versions without reviewing the associated content changes. This flaw poses significant risks to the approval process, leading to unauthorized actions that compromise the integrity of file management.

Affected Version(s)

Approval 1.0.0 <= 3.0.0

References

CVSS V3.0

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dang Hung Vi (vidang04)
.