PT-2026-95208 · Nextcloud · Nextcloud

·

CVE-2026-77164

·

Published

2026-09-18

·

Updated

2026-09-25

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud (affected versions not specified)
Description Remote-instance signature verification in Circles fetches the keyId URL provided by an attacker before trust is established. This process explicitly allows local or private addresses, bypassing core Server-Side Request Forgery (SSRF) protections. SSRF is a flaw that allows an attacker to induce the server-side application to make requests to an unintended location. The public, unauthenticated endpoints 'POST /apps/circles/event/' and 'POST /apps/circles/incoming/' reach this code path, enabling any unauthenticated user to force the server to issue a GET request to an internal address. This is a blind SSRF, meaning the response body is not returned to the requester, but an attacker can still determine if an internal service is reachable.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-NEXTCLOUD-2026-77164
CVE-2026-77164

Affected Products

Nextcloud