CVE-2026-82982: Medium severity Approval app vulnerability

Published Sep 18, 2026
·
Updated

The Approval app's approve/reject endpoint is meant to require the file's current etag as a freshness check, preventing an approver from approving or rejecting a file whose contents changed after they reviewed it. The backend only enforced this check when the etag parameter was present and non-empty in the request. An attacker able to intercept and modify the approval request could omit the etag field entirely, bypassing the freshness check and approving or rejecting a file version they never reviewed.

Affected Software

1 affected component
Approval app

Event History

Sep 18, 2026
CVE Published
via MITRE·01:26 AM
Data Sourced
via MITRE·01:26 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What access and capabilities are needed to exploit this issue?

An attacker needs privileges to submit approval or rejection requests and must be able to intercept and modify the approval request before it reaches the backend. They can exploit the issue by removing the etag parameter or sending it empty.

2

What is the practical impact?

The attacker can approve or reject a file whose contents changed after the approver reviewed it. The issue affects integrity of the approval workflow; no confidentiality or availability impact is described.

3

How can teams reduce risk if they cannot apply a fix immediately?

Ensure approval requests cannot be modified in transit and monitor approval or rejection activity involving files that changed after review. Validate that requests include a non-empty etag before allowing the approval action.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203