Remote Instance Signature Verification Flaw in Circles by Nextcloud
CVE-2026-77164

6.2MEDIUM

Key Information:

Vendor

Nextcloud

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-77164?

A security vulnerability in Circles by Nextcloud allows attackers to exploit the remote-instance signature verification process. The flaw arises from the system fetching the attacker-controlled keyId URL without properly establishing trust beforehand. Notably, it allows requests to local or private addresses, thereby circumventing Nextcloud's internal SSRF protections. Consequently, specific endpoints become targets for unauthenticated users to manipulate the server into executing GET requests to internal services. While these attacks allow attackers to verify the reachability of internal services, the blind nature of this SSRF means that the actual response content from the internal request is not disclosed, enhancing the criticality of the risk involved.

Affected Version(s)

Server 31.0.0 <= 32.0.0

References

CVSS V3.0

Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Balvant Chavda (0x0doteth)
.