CVE-2026-23989
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
06/02/2026
Last modified:
24/02/2026
Description
REVA is an interoperability platform. Prior to 2.42.3 and 2.40.3, a bug in the GRPC authorization middleware of the "Reva" component of OpenCloud allows a malicious user to bypass the scope verification of a public link. By exploiting this via the the "archiver" service this can be leveraged to create an archive (zip or tar-file) containing all resources that this creator of the public link has access to. This vulnerability is fixed in 2.42.3 and 2.40.3.
Impact
Base Score 3.x
8.20
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:heinlein:opencloud_reva:*:*:*:*:*:*:*:* | 2.40.3 (excluding) | |
| cpe:2.3:a:heinlein:opencloud_reva:*:*:*:*:*:*:*:* | 2.41.0 (including) | 2.42.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



