Vulnerability Description
REVA is an interoperability platform. Prior to 2.42.3 and 2.40.3, a bug in the GRPC authorization middleware of the "Reva" component of OpenCloud allows a malicious user to bypass the scope verification of a public link. By exploiting this via the the "archiver" service this can be leveraged to create an archive (zip or tar-file) containing all resources that this creator of the public link has access to. This vulnerability is fixed in 2.42.3 and 2.40.3.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Heinlein | Opencloud Reva | < 2.40.3 |
Related Weaknesses (CWE)
References
- https://github.com/opencloud-eu/reva/commit/95aa2bc5d980eaf6cc134d75782b4f5ac7b3Patch
- https://github.com/opencloud-eu/reva/security/advisories/GHSA-9j2f-3rj3-wgpgVendor Advisory
FAQ
What is CVE-2026-23989?
CVE-2026-23989 is a vulnerability with a CVSS score of 8.2 (HIGH). REVA is an interoperability platform. Prior to 2.42.3 and 2.40.3, a bug in the GRPC authorization middleware of the "Reva" component of OpenCloud allows a malicious user to bypass the scope verificati...
How severe is CVE-2026-23989?
CVE-2026-23989 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-23989?
Check the references section above for vendor advisories and patch information. Affected products include: Heinlein Opencloud Reva.