PT-2025-49295 · Nextcloud · Nextcloud Approval App

Published

2025-12-05

·

Updated

2025-12-09

·

CVE-2025-66515

CVSS v3.1

2.7

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud Approval app versions prior to 1.3.1 Nextcloud Approval app versions prior to 2.5.0
Description The Nextcloud Approval app has an issue where an authenticated user, listed as a requester in a workflow, can set another user’s file to “pending approval” without having access to the file. This is achieved by using the numeric file id.
Recommendations Update to Nextcloud Approval app version 1.3.1 or later. Update to Nextcloud Approval app version 2.5.0 or later.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-66515
GHSA-Q26G-FMJQ-X5G5

Affected Products

Nextcloud Approval App