๐Ÿ” CVE Alert

CVE-2026-84282

MEDIUM 6.5

A Server-Side Request Forgery (SSRF) vulnerability exists in the ONLYOFFICE ownCloud Integration plugin (version 9.12)

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

A Server-Side Request Forgery (SSRF) vulnerability exists in the ONLYOFFICE ownCloud Integration plugin version 9.12. The /apps/onlyoffice/ajax/settings/address endpoint does not sufficiently validate the user-supplied Document Server URL before initiating outbound connections. An authenticated administrator can manipulate the document server parameter to cause the ownCloud server to send arbitrary requests to attacker-controlled destinations, including localhost and internal network hosts. This allows internal network reconnaissance and TCP port scanning based on differences in server responses.

Vendor ascensio system sia / onlyoffice
Product onlyoffice owncloud integration plugin
Published Sep 8, 2026
Last Updated Sep 10, 2026
Stay Ahead of the Next One

Get instant alerts for ascensio system sia / onlyoffice onlyoffice owncloud integration plugin

Be the first to know when new medium vulnerabilities affecting ascensio system sia / onlyoffice onlyoffice owncloud integration plugin are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Ascensio System SIA / OnlyOffice / ONLYOFFICE ownCloud integration plugin
9.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/ONLYOFFICE/onlyoffice-owncloud/blob/master/controller/settingsapicontroller.php kb.cert.org: https://kb.cert.org/vuls/id/943094 kb.cert.org: https://www.kb.cert.org/vuls/id/943094