CVE-2025-66515: Nextcloud Approval app allows users to request approval for other users file
The Nextcloud Approval app allows approval or disapproval of files in the sidebar. Prior to 1.3.1 and 2.5.0, an authenticated user listed as a requester in a workflow can set another user’s file into the “pending approval” without access to the file by using the numeric file id. This vulnerability is fixed in 1.3.1 and 2.5.0.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66515?
CVE-2025-66515 is considered a moderate severity vulnerability due to the potential unauthorized access to file approval functionality.
How do I fix CVE-2025-66515?
To fix CVE-2025-66515, upgrade the Nextcloud Approval app to version 1.3.1 or 2.5.0 or later.
Who is affected by CVE-2025-66515?
CVE-2025-66515 affects any Nextcloud instance running the Approval app versions prior to 1.3.1 and 2.5.0.
What does CVE-2025-66515 allow an attacker to do?
CVE-2025-66515 allows an authenticated user to set another user's file into a pending approval state without having access to that file.
Is CVE-2025-66515 related to unauthorized file access?
Yes, CVE-2025-66515 is related to unauthorized manipulation of file approval processes by users who should not have permission.