CVE-2023-49791

    Dashboard / Vulnerabilities / CVE-2023-49791

    CVE-2023-49791

    Published: 22 Dec 2023Last Modified: 12 Aug 2026

    Summary: Workflows do not require password confirmation on API level

    Details: Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. In Nextcloud Server prior to versions 26.0.9 and 27.1.4; as well as Nextcloud Enterprise Server prior to versions 23.0.12.13, 24.0.12.9, 25.0.13.4, 26.0.9, and 27.1.4; when an attacker manages to get access to an active session of another user via another way, they could delete and modify workflows by sending calls directly to the API bypassing the password confirmation shown in the UI. Nextcloud Server versions 26.0.9 and 27.1.4 and Nextcloud Enterprise Server versions 23.0.12.13, 24.0.12.9, 25.0.13.4, 26.0.9, and 27.1.4 contain a patch for this issue. No known workarounds are available.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 62cfd3b4c9ff4d8cdbbe6dcc8b63a1085bb94e3d

    Affected versions

    v27.1.4rc1
    v27.1.3
    v27.1.3rc2
    v27.1.3rc1
    v27.1.2
    v27.1.2rc1
    v27.1.1
    v27.1.0
    v27.1.0rc4
    v27.1.0rc3
    v27.1.0rc2
    v27.1.0rc1
    v27.1.0beta3
    v27.1.0beta2

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2023-49791 | CVE-DB