Any authenticated user can lock or unlock files they do not own by targeting absolute WebDAV paths of other users. The DAV plugin resolves files from the absolute request URI without verifying that the path segment matches the authenticated session user. This
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Nextcloud | Files Lock | 31.0.0 ~ 33.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-77169 | Nextcloud团队文件夹应用权限绕过漏洞 | |
| CVE-2026-77170 | Deck配置API越权设置任意看板配置漏洞 | |
| CVE-2026-77164 | Nextcloud Circles盲SSRF漏洞 | |
| CVE-2026-82982 | CVE-2026-82982 | |
| CVE-2026-82985 | CVE-2026-82985 | |
| CVE-2026-68493 | CVE-2026-68493 |
No comments yet