Nextcloud Approval App Unauthorized Workflow Manipulation Vulnerability (CVE-2025-66515) — Low Severity

Overview

A security flaw has been identified in the Nextcloud Approval app that could allow a specific type of unauthorized action. This vulnerability means that an authenticated user who is already a “requester” in a workflow could potentially set another user’s file into a “pending approval” state, even if they don’t have direct access to that file. This happens by exploiting how the app handles numeric file IDs. While the impact is low, it’s important for users to understand and address this issue to maintain proper file management and security within their Nextcloud instances.

CVE Details

  • Product: Nextcloud Approval App
  • Published Date: December 5, 2025
  • Severity: Low
  • Status: Analyzed

Affected Products

The Nextcloud Approval app versions prior to 1.3.1 and 2.5.0 are affected by this vulnerability. If you are using any version of the Approval app older than these, your system may be at risk.

Current Status

This vulnerability has been analyzed and publicly disclosed. Nextcloud has released updates to address the issue, indicating that a fix is available.

Severity Level

The Common Vulnerability Scoring System (CVSS) rates this vulnerability with a score of 2.7, classifying it as Low severity. This means that while the vulnerability is real, its potential impact on confidentiality, integrity, or availability is limited. Exploiting this flaw requires an authenticated user with existing workflow requester privileges, and it primarily affects the workflow status of a file rather than granting unauthorized access to the file’s content or full control over it.

Possible Solutions

The good news is that a fix is readily available for this vulnerability. Nextcloud has released updated versions of the Approval app that include a crucial security check. The fix, as seen in the commit details, introduces a verification step to ensure that a user attempting to initiate an approval workflow on a file actually has legitimate access to it.

To protect your Nextcloud instance from this vulnerability, you should:

  1. Update Immediately: Upgrade your Nextcloud Approval app to version 1.3.1 or 2.5.0, or newer. These versions contain the necessary security patches.
  2. Regular Updates: Always keep your Nextcloud installation and all its applications updated to the latest stable versions. This is a general best practice for maintaining a secure environment.
  3. Review Permissions: Regularly audit user permissions and workflow configurations within your Nextcloud instance to ensure that users only have the access levels they require.

References

https://github.com/nextcloud/approval/commit/e30b56b7832255311ac800b7875f44866e88fff4
https://github.com/nextcloud/approval/pull/334
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-q26g-fmjq-x5g5
https://hackerone.com/reports/3338748

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.