Authentication Bypass in Nextcloud MCP Server
CVE-2026-55640
9.1CRITICAL
What is CVE-2026-55640?
The Nextcloud MCP Server lacks necessary authentication for the POST /webhooks/nextcloud endpoint prior to version 0.117.2. The default configuration results in the WEBHOOK_SECRET being unset, allowing unauthenticated requests to be processed. This vulnerability permits an attacker to exploit the handle_nextcloud_webhook() function, enabling them to delete or manipulate vector embeddings for any user without an authentication check. Consequently, attackers can destroy the semantic search index by forging deletion events. A fix is available in version 0.117.2.
Affected Version(s)
nextcloud-mcp-server < 0.117.2
