Server-Side Request Forgery in ONLYOFFICE ownCloud Integration Plugin
CVE-2026-84282

Currently unrated

What is CVE-2026-84282?

A Server-Side Request Forgery (SSRF) vulnerability exists in the ONLYOFFICE ownCloud Integration plugin version 9.12. The flaw is rooted in the /apps/onlyoffice/ajax/settings/address endpoint, which fails to adequately validate the Document Server URL input provided by authenticated administrators. As a result, this oversight allows manipulation of the server settings, which can lead to malicious requests being sent from the ownCloud server to unauthorized destinations, including internal hosts and localhost. The exploitation of this vulnerability can facilitate internal network reconnaissance and TCP port scanning, posing serious risks to organizational security.

Affected Version(s)

ONLYOFFICE ownCloud integration plugin 9.12

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.