CVE-2026-77166

Summary

The emoji field in the page emoji update endpoint does not properly validate user input. By injecting long text and line breaks, the sidebar layout becomes broken and can hide other items.

Affected Software

VendorProductVersion RangeStatus
NextcloudCollectives3.2.1 <= 3.5.0affected

Weaknesses

  • CWE-840: CWE-840 Business Logic Errors

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: no
    • Technical Impact: partial

Additional References

References