Cross-user manual locks : attacker locks a victim's files, blocking writes (PUT/MOVE/DELETE, editor saves).
Lock-token disclosure: the app returns the lock token to unauthorized callers, enabling them to remove token-based locks (client locks) of other users.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://hackerone.com/reports/3301553 |
|
Sat, 19 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Arbitrary Cross‑User File Locking via WebDAV Paths |
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 18 Sep 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nextcloud
Nextcloud files Lock |
|
| Vendors & Products |
Nextcloud
Nextcloud files Lock |
Fri, 18 Sep 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Any authenticated user can lock or unlock files they do not own by targeting absolute WebDAV paths of other users. The DAV plugin resolves files from the absolute request URI without verifying that the path segment matches the authenticated session user. This enables: Cross-user manual locks : attacker locks a victim's files, blocking writes (PUT/MOVE/DELETE, editor saves). Lock-token disclosure: the app returns the lock token to unauthorized callers, enabling them to remove token-based locks (client locks) of other users. | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV3_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2026-09-18T19:42:58.732Z
Reserved: 2026-08-31T15:00:00.543Z
Link: CVE-2026-82980
Updated: 2026-09-18T19:42:54.319Z
Status : Deferred
Published: 2026-09-18T02:17:07.910
Modified: 2026-09-18T20:17:25.647
Link: CVE-2026-82980
No data.
OpenCVE Enrichment
Updated: 2026-09-19T21:15:06Z