๐Ÿ” CVE Alert

CVE-2026-82980

MEDIUM 6.3
CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th

Any authenticated user can lock or unlock files they do not own by targeting absolute WebDAV paths of other users. The DAV plugin resolves files from the absolute request URI without verifying that the path segment matches the authenticated session user. This enables: Cross-user manual locks : attacker locks a victim's files, blocking writes (PUT/MOVE/DELETE, editor saves). Lock-token disclosure: the app returns the lock token to unauthorized callers, enabling them to remove token-based locks (client locks) of other users.

CWE CWE-287
Vendor nextcloud
Product files lock
Published Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for nextcloud files lock

Be the first to know when new medium vulnerabilities affecting nextcloud files lock are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Affected Versions

Nextcloud / Files Lock
31.0.0 โ‰ค 33.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
hackerone.com: https://hackerone.com/reports/3301553

Credits

Balvant Chavda (0x0doteth)