CVE-2026-82980

CVE-2026-82980 published: Any authenticated user can lock or unlock files they do not own by targeting absolute WebDAV paths of other users. The DAV plugin resolves files from the absolute request URI without verifying that the path segment matches the authenticated session user. Th...

View full NVD advisory → ← Back to CVE watch