Remote Instance Signature Verification Flaw in Circles by Nextcloud
CVE-2026-77164
What is CVE-2026-77164?
A security vulnerability in Circles by Nextcloud allows attackers to exploit the remote-instance signature verification process. The flaw arises from the system fetching the attacker-controlled keyId URL without properly establishing trust beforehand. Notably, it allows requests to local or private addresses, thereby circumventing Nextcloud's internal SSRF protections. Consequently, specific endpoints become targets for unauthenticated users to manipulate the server into executing GET requests to internal services. While these attacks allow attackers to verify the reachability of internal services, the blind nature of this SSRF means that the actual response content from the internal request is not disclosed, enhancing the criticality of the risk involved.
Affected Version(s)
Server 31.0.0 <= 32.0.0