Server-Side Request Forgery in ONLYOFFICE ownCloud Integration Plugin
CVE-2026-84282
Currently unrated
Key Information:
- Vendor
- CVE Published:
- 8 September 2026
What is CVE-2026-84282?
A Server-Side Request Forgery (SSRF) vulnerability exists in the ONLYOFFICE ownCloud Integration plugin version 9.12. The flaw is rooted in the /apps/onlyoffice/ajax/settings/address endpoint, which fails to adequately validate the Document Server URL input provided by authenticated administrators. As a result, this oversight allows manipulation of the server settings, which can lead to malicious requests being sent from the ownCloud server to unauthorized destinations, including internal hosts and localhost. The exploitation of this vulnerability can facilitate internal network reconnaissance and TCP port scanning, posing serious risks to organizational security.
Affected Version(s)
ONLYOFFICE ownCloud integration plugin 9.12
