CVE-2025-66515 Details
Description
The Nextcloud Approval app allows approval or disapproval of files in the sidebar. Prior to 1.3.1 and 2.5.0, an authenticated user listed as a requester in a workflow can set another user’s file into the “pending approval” without access to the file by using the numeric file id. This vulnerability is fixed in 1.3.1 and 2.5.0.
A vulnerability in the Nextcloud Approval app prior to versions 1.3.1 and 2.5.0 allows authenticated users listed as requesters in a workflow to place another user's file into 'pending approval' status without having access to the file. This is achieved by using the numeric file ID.
Users are advised to upgrade the Nextcloud Approval app to version 2.5.0 or 1.3.1. Alternatively, the Approval app can be disabled.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 5, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/nextcloud/approval/commit/e30b56b7832255311ac800b7875f44866e88fff4 | [email protected] | Patch |
| https://github.com/nextcloud/approval/pull/334 | [email protected] | Issue Tracking |
| https://github.com/nextcloud/security-advisories/security/advisories/GHSA-q26g-fmjq-x5g5 | [email protected] | PatchVendor Advisory |
| https://hackerone.com/reports/3338748 | [email protected] | Issue TrackingVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| nextcloud approval | >= 1.0.0, < 1.3.1 >= 2.0.0, < 2.5.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 9, 2025 | Initial Analysis | [email protected] |
| Dec 5, 2025 | New CVE Received | [email protected] |