CVE-2026-23989 is a high-severity vulnerability affecting the REVA component of OpenCloud, specifically versions prior to 2.42.3 and 2.40.3. A flaw in the GRPC authorization middleware allows a malicious authenticated user to bypass scope verification for public links. This bypass can be leveraged through the "archiver" service to create archives containing all resources accessible to the public link creator. The vulnerability has a CVSS score of 8.1 (High), indicating a low attack complexity and requiring only low privileges, with a significant impact on confidentiality and integrity. While no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available, and it is not listed in the KEV catalog, the vulnerability has garnered some community discussion and media coverage. Organizations utilizing affected OpenCloud REVA versions should prioritize patching to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.40.3CPE matchmatch criteria | cpe:2.3:a:heinlein:opencloud_reva:*:*:*:*:*:*:*:* | ||
>= 2.41.0, < 2.42.3CPE matchmatch criteria | cpe:2.3:a:heinlein:opencloud_reva:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.