PT-2026-87103 · Ascensio System Sia / Onlyoffice · Onlyoffice Owncloud Integration Plugin

CVE-2026-84282

·

Publicado

2026-09-08

·

Atualizado

2026-09-08

CVSS v3.1

6.5

Média

VetorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
An authenticated admin can turn the ownCloud server into a proxy for internal network reconnaissance. The ONLYOFFICE integration plugin (version 9.12) fails to validate the document server URL before initiating outbound connections, allowing an attacker to probe internal hosts or localhost services.
Technical Breakdown: - CVE: CVE-2026-84282 - Attack Vector: Crafted POST requests to /apps/onlyoffice/ajax/settings/address - Privilege Required: Authenticated administrator - Impact: SSRF enabling internal network scanning, access to cloud metadata endpoints, or interaction with internal services - No IOCs provided – exploitation is configuration-based, not payload-driven
Defense: Restrict admin access to the ONLYOFFICE settings panel, apply input validation on the document server URL parameter, and enforce network segmentation to limit outbound traffic from the ownCloud server to only known, trusted endpoints.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-84282

Produtos afetados

Onlyoffice Owncloud Integration Plugin