CVE-2026-82980
CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th
Any authenticated user can lock or unlock files they do not own by targeting absolute WebDAV paths of other users. The DAV plugin resolves files from the absolute request URI without verifying that the path segment matches the authenticated session user. This enables: Cross-user manual locks : attacker locks a victim's files, blocking writes (PUT/MOVE/DELETE, editor saves). Lock-token disclosure: the app returns the lock token to unauthorized callers, enabling them to remove token-based locks (client locks) of other users.
| CWE | CWE-287 |
| Vendor | nextcloud |
| Product | files lock |
| Published | Sep 18, 2026 |
Stay Ahead of the Next One
Get instant alerts for nextcloud files lock
Be the first to know when new medium vulnerabilities affecting nextcloud files lock are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L Affected Versions
Nextcloud / Files Lock
31.0.0 โค 33.0.0
Credits
Balvant Chavda (0x0doteth)