Executive brief
Nextcloud is an open-source platform used for file sharing and team collaboration. A security flaw in the Approval application allows logged-in users to determine if specific files are linked to internal approval workflows, even if they shouldn't have access to that information. This could lead to the disclosure of sensitive internal processes or the existence of restricted files.
Technical details
An information disclosure vulnerability exists in the Nextcloud Approval app prior to version 2.7.2. The application fails to properly validate file access permissions when a user requests workflow rules associated with a specific 'fileId'. An authenticated attacker can exploit this by providing arbitrary file identifiers to determine if those files are part of an approval process. This bypasses intended visibility restrictions regarding which files are subject to administrative or team approval workflows. The issue is addressed in version 2.7.2 by implementing stricter access permission checks during rule requests.
Affected products
- Nextcloud Approval app < 2.7.2
Timeline
- 2026-01-08: patched: Fix merged into main branch via pull request 356
- 2026-05-12: advisory: Vendor security advisory published via GitHub
- 2026-06-01: disclosed: CVE published to NVD