The Nextcloud Approval app allows approval or disapproval of files in the sidebar. Prior to 1.3.1 and 2.5.0, an authenticated user listed as a requester in a workflow can set another user’s file into the “pending approval” without access to the file by using the numeric file id. This vulnerability is fixed in 1.3.1 and 2.5.0.
History

Fri, 05 Dec 2025 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Nextcloud
Nextcloud approval
Vendors & Products Nextcloud
Nextcloud approval

Fri, 05 Dec 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 05 Dec 2025 17:45:00 +0000

Type Values Removed Values Added
Description The Nextcloud Approval app allows approval or disapproval of files in the sidebar. Prior to 1.3.1 and 2.5.0, an authenticated user listed as a requester in a workflow can set another user’s file into the “pending approval” without access to the file by using the numeric file id. This vulnerability is fixed in 1.3.1 and 2.5.0.
Title Nextcloud Approval app allows users to request approval for other users file
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-12-05T17:37:06.767Z

Updated: 2025-12-05T18:10:00.615Z

Reserved: 2025-12-03T15:28:02.992Z

Link: CVE-2025-66515

cve-icon Vulnrichment

Updated: 2025-12-05T18:09:54.033Z

cve-icon NVD

Status : Received

Published: 2025-12-05T18:15:57.623

Modified: 2025-12-05T18:15:57.623

Link: CVE-2025-66515

cve-icon Redhat

No data.