PT-2026-87103 · Ascensio System Sia / Onlyoffice · Onlyoffice Owncloud Integration Plugin
CVE-2026-84282
·
Publicado
2026-09-08
·
Atualizado
2026-09-08
CVSS v3.1
6.5
Média
| Vetor | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
An authenticated admin can turn the ownCloud server into a proxy for internal network reconnaissance. The ONLYOFFICE integration plugin (version 9.12) fails to validate the document server URL before initiating outbound connections, allowing an attacker to probe internal hosts or localhost services.
Technical Breakdown: - CVE: CVE-2026-84282 - Attack Vector: Crafted POST requests to /apps/onlyoffice/ajax/settings/address - Privilege Required: Authenticated administrator - Impact: SSRF enabling internal network scanning, access to cloud metadata endpoints, or interaction with internal services - No IOCs provided – exploitation is configuration-based, not payload-driven
Defense: Restrict admin access to the ONLYOFFICE settings panel, apply input validation on the document server URL parameter, and enforce network segmentation to limit outbound traffic from the ownCloud server to only known, trusted endpoints.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Onlyoffice Owncloud Integration Plugin