CVE Explorer
CVE-2026-23989
REVA is an interoperability platform. Prior to 2.42.3 and 2.40.3, a bug in the GRPC authorization middleware of the "Reva" component of OpenCloud allows a malicious user to bypass the scope verification of a public link. By exploiting this via the the "archiver" service this can be leveraged to create an archive (zip or tar-file) containing all resources that this creator of the public link has access to. This vulnerability is fixed in 2.42.3 and 2.40.3.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"reva","vendor":"opencloud-eu","versions":[{"status":"affected","version":"< 2.40.3"},{"status":"affected","version":">= 2.41.0, < 2.42.3"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:592f0b0a1afccf84cbb52e7d01417dcbd706abbcf3cf27888bd60fe038f1768e · sha256:8e8895d9d48fdf54… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":8.2,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:592f0b0a1afccf84cbb52e7d01417dcbd706abbcf3cf27888bd60fe038f1768e · sha256:8e8895d9d48fdf54… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-863","description":"CWE-863: Incorrect Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:592f0b0a1afccf84cbb52e7d01417dcbd706abbcf3cf27888bd60fe038f1768e · sha256:8e8895d9d48fdf54… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/opencloud-eu/reva/commit/95aa2bc5d980eaf6cc134d75782b4f5ac7b36ae1","tags":["x_refsource_MISC"],"url":"https://github.com/opencloud-eu/reva/commit/95aa2bc5d980eaf6cc134d75782b4f5ac7b36ae1"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:592f0b0a1afccf84cbb52e7d01417dcbd706abbcf3cf27888bd60fe038f1768e · sha256:8e8895d9d48fdf54… · /containers/cna/references/1
{"name":"https://github.com/opencloud-eu/reva/security/advisories/GHSA-9j2f-3rj3-wgpg","tags":["x_refsource_CONFIRM"],"url":"https://github.com/opencloud-eu/reva/security/advisories/GHSA-9j2f-3rj3-wgpg"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:592f0b0a1afccf84cbb52e7d01417dcbd706abbcf3cf27888bd60fe038f1768e · sha256:8e8895d9d48fdf54… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.