Junglewise Threat Intelligence

CVE-2026-45277: Nextcloud Approval app information disclosure via fileId parameter

CVE-2026-45277 · Severity: low · CVSS 3.3 · Published 2026-06-01

Technologies: Nextcloud Approval. Vendors: Nextcloud.

Executive brief

Nextcloud is an open-source platform used for file sharing and team collaboration. A security flaw in the Approval application allows logged-in users to determine if specific files are linked to internal approval workflows, even if they shouldn't have access to that information. This could lead to the disclosure of sensitive internal processes or the existence of restricted files.

Technical details

An information disclosure vulnerability exists in the Nextcloud Approval app prior to version 2.7.2. The application fails to properly validate file access permissions when a user requests workflow rules associated with a specific 'fileId'. An authenticated attacker can exploit this by providing arbitrary file identifiers to determine if those files are part of an approval process. This bypasses intended visibility restrictions regarding which files are subject to administrative or team approval workflows. The issue is addressed in version 2.7.2 by implementing stricter access permission checks during rule requests.

Affected products

  • Nextcloud Approval app < 2.7.2

Timeline

  • 2026-01-08: patched: Fix merged into main branch via pull request 356
  • 2026-05-12: advisory: Vendor security advisory published via GitHub
  • 2026-06-01: disclosed: CVE published to NVD

References

Related threats