CVE-2026-84282
N/A
N/A
Summary
A Server-Side Request Forgery (SSRF) vulnerability exists in the ONLYOFFICE ownCloud Integration plugin version 9.12. The /apps/onlyoffice/ajax/settings/address endpoint does not sufficiently validate the user-supplied Document Server URL before initiating outbound connections. An authenticated administrator can manipulate the document server parameter to cause the ownCloud server to send arbitrary requests to attacker-controlled destinations, including localhost and internal network hosts. This allows internal network reconnaissance and TCP port scanning based on differences in server responses.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Ascensio System SIA / OnlyOffice | ONLYOFFICE ownCloud integration plugin | 9.12 | affected |
Weaknesses
- CWE-918 Server-Side Request Forgery (SSRF)
- CWE-20 Improper Input Validation
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
ADP Enrichment
CVE Program Container
Additional References
References
- https://github.com/ONLYOFFICE/onlyoffice-owncloud/blob/master/controller/settingsapicontroller.php
- https://kb.cert.org/vuls/id/943094
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.