Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-82982

Quick assessment

Affected
Nextcloud Approval
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Approval 应用的批准/拒绝接口旨在要求提供文件的当前 etag 作为新鲜度检查,以防止审批者批准或拒绝在审核之后内容发生变化的文件。然而,后端仅在请求中提供且非空的 etag 参数存在时才执行该检查。如果攻击者能够拦截并修改审批请求,他们可以完全省略 etag 字段,从而绕过新鲜度检查,批准或拒绝他们从未审核过的文件版本。

AI Predicted 6.5 Difficulty: Easy EPSS 0.19% · P9

Affected Version Matrix 1

VendorProduct Version RangeStatus
Nextcloud Approval 1.0.0≤ 3.0.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-82982

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
The Approval app's approve/reject endpoint is meant to require the file's current etag as a freshness check, preventing an approver from approving or rejecting a file whose contents changed after they reviewed it. The backend only enforced this check when the etag parameter was present and non-empty in the request. An attacker able to intercept and modify the approval request could omit the etag field entirely, bypassing the freshness check and approving or rejecting a file version they never reviewed.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
业务逻辑错误
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Nextcloud Approval 1.0.0 ~ 3.0.0 -

II. Public POCs for CVE-2026-82982

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-82982

登录查看更多情报信息。

Other References for CVE-2026-82982 (1)

Same Patch Batch · Nextcloud · 2026-09-18 · 7 CVEs total

CVE-2026-77169 Nextcloud团队文件夹应用权限绕过漏洞
CVE-2026-77170 Deck配置API越权设置任意看板配置漏洞
CVE-2026-77164 Nextcloud Circles盲SSRF漏洞
CVE-2026-82980 DAV插件跨用户文件锁定漏洞
CVE-2026-82985 Nextcloud Photos智能相册共享文件泄露漏洞
CVE-2026-68493 用户猜测复杂ID可越权获取圈子成员列表

IV. Related Vulnerabilities

V. Comments for CVE-2026-82982

No comments yet


Leave a comment