CVE-2026-23989Disclosure(heinlein / opencloud_reva)

LOWCVSS 8.1 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for heinlein opencloud_reva systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

REVA is an interoperability platform. Prior to 2.42.3 and 2.40.3, a bug in the GRPC authorization middleware of the "Reva" component of OpenCloud allows a malicious user to bypass the scope verification of a public link. By exploiting this via the the "archiver" service this can be leveraged to create an archive (zip or tar-file) containing all resources that this creator of the public link has access to. This vulnerability is fixed in 2.42.3 and 2.40.3.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • opencloud_reva

Threat summary

  • Public PoC and exploit tooling are both present
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-02-06); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
opencloud_reva

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-02-06: 2Mentions · 2026-02-08: 1Mentions · 2026-08-29: 1Mentions · 2026-08-30: 1PoC Mentioned / Linked · 2026-08-29: 1PoC Mentioned / Linked · 2026-08-30: 1Exploit Tool / Code · 2026-08-29: 1Exploit Tool / Code · 2026-08-30: 1Technical Details · 2026-02-06: 2Technical Details · 2026-08-29: 1Technical Details · 2026-08-30: 102-0602-0808-2908-30
Signal classification3 categories
Disclosure
240.0%
PoC
240.0%
General
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-062
Disclosure2
2026-02-081
General1
2026-08-291
PoC1
2026-08-301
PoC1
Full discourse5 posts
  • Nicolas Krassas@Dinosn
    PoC

    CVE-2026-23989 — OpenCloud / ownCloud Infinite Scale public-link scope bypass https://github.com/dinosn/cve-2026-23989-opencloud-lab

    Post summary

    A GitHub repository is shared that appears to host a Proof of Concept for CVE‑2026‑23989, detailing a public‑link scope bypass but with no indication of active exploitation or remediation advice.

    12128266.3K
    162.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-23989 REVA is an interoperability platform. Prior to 2.42.3 and 2.40.3, a bug in the GRPC authorization middleware of the "Reva" component of OpenCloud allows a malicious u… https://www.cve.org/CVERecord?id=CVE-2026-23989

    Post summary

    CVE‑2026‑23989 identifies a bug in the GRPC authorization middleware of OpenCloud's Reva component, potentially allowing malicious use. No PoC, exploit, patch, or active exploitation details are provided.

    00010193
    56.5K followersView on X
  • ✪ 𝕱𝖆𝖍𝖆𝖉@fad_777
    PoC

    ثغرات public-link scope bypass قد تحوّل رابط مشاركة محدود إلى مسار وصول غير متوقع. CVE-2026-23989 يخص OpenCloud و ownCloud Infinite Scale، ويرتبط بتجاوز نطاق الروابط العامة. أهمية الثغرة تأتي من اعتماد منصات مشاركة الملفات على ضبط الصلاحيات بدقة، خصوصًا عند استخدام روابط عامة للوصول إلى محتوى محدد. القيمة التقنية هنا هي مراجعة كيفية فرض scope على مستوى الخادم، وليس الاكتفاء بخصائص الرابط أو واجهة الاستخدام. عمليًا، يستحق الأمر متابعة التحديثات الرسمية، مراجعة الروابط العامة النشطة، والتحقق من سجلات الوصول عند تشغيل OpenCloud أو ownCloud Infinite Scale. Public-link scope bypasses are risky because they challenge one of the core assumptions in file-sharing systems: shared links should expose only what their scope allows. CVE-2026-23989 affects OpenCloud / ownCloud Infinite Scale and points to a public-link authorization boundary that needs attention. For security teams, the key lesson is to validate scope enforcement server-side and review how public links are created, stored, and checked at request time. For operators, this is a good trigger to monitor vendor guidance, audit active public shares, and verify access logs for unexpected public-link usage. https://github.com/dinosn/cve-2026-23989-opencloud-lab #CVE202623989 #ownCloud #CloudSecurity

    Post summary

    The post highlights a public‑link scope bypass flaw (CVE‑2026‑23989) in OpenCloud/ownCloud Infinite Scale, shares a GitHub link to a PoC, and recommends monitoring and auditing access logs for suspicious activity.

    00000104
    86 followersView on X
  • PulsePatch.io@pulsepatchio
    General

    A high severity public link exploit (CVE-2026-23989) impacts OpenCloud REVA. Organizations using REVA should review their configurations and prepare for an update. #infosec #REVA https://www.pulsepatch.io/posts/cve-2026-23989-reva-public-link-exploit

    Post summary

    The message alerts to a high‑severity public‑link exploit for CVE‑2026‑23989 in OpenCloud REVA, urging configuration review and awaiting an update, but offers no PoC, exploit code, patch, or technical depth.

    0000057
    1 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-23989 - High REVA is an interoperability platform. Prior to 2.42.3 and 2.40.3, a bug in the GRPC authorization middleware of the "Reva" component of OpenCloud allows a malicious user to bypass the scope v... https://www.thehackerwire.com/vulnerability/CVE-2026-23989/ https://t.co/SFFUX7F1sl

    Post summary

    The post announces a high‑severity CVE-2026‑23989 in REVA’s GRPC authorization, noting a scope bypass flaw; no PoC, exploit, active use, patch, or false‑positive claim is mentioned.

    0000061
    113 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appheinleinopencloud_reva---

Explore more