PT-2026-87103 · Ascensio System Sia / Onlyoffice · Onlyoffice Owncloud Integration Plugin
CVE-2026-84282
·
Published
2026-09-08
·
Updated
2026-09-08
CVSS v3.1
6.5
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
An authenticated admin can turn the ownCloud server into a proxy for internal network reconnaissance. The ONLYOFFICE integration plugin (version 9.12) fails to validate the document server URL before initiating outbound connections, allowing an attacker to probe internal hosts or localhost services.
Technical Breakdown: - CVE: CVE-2026-84282 - Attack Vector: Crafted POST requests to /apps/onlyoffice/ajax/settings/address - Privilege Required: Authenticated administrator - Impact: SSRF enabling internal network scanning, access to cloud metadata endpoints, or interaction with internal services - No IOCs provided – exploitation is configuration-based, not payload-driven
Defense: Restrict admin access to the ONLYOFFICE settings panel, apply input validation on the document server URL parameter, and enforce network segmentation to limit outbound traffic from the ownCloud server to only known, trusted endpoints.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Onlyoffice Owncloud Integration Plugin