CVE-2026-84282
Deferred Deferred - Pending Action

Server-Side Request Forgery in ONLYOFFICE ownCloud Integration Plugin

Vulnerability report for CVE-2026-84282, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-10

Assigner: CERT/CC

Description

A Server-Side Request Forgery (SSRF) vulnerability exists in the ONLYOFFICE ownCloud Integration plugin version 9.12. The /apps/onlyoffice/ajax/settings/address endpoint does not sufficiently validate the user-supplied Document Server URL before initiating outbound connections. An authenticated administrator can manipulate the document server parameter to cause the ownCloud server to send arbitrary requests to attacker-controlled destinations, including localhost and internal network hosts. This allows internal network reconnaissance and TCP port scanning based on differences in server responses.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-10
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
onlyoffice owncloud_integration 9.12

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Server-Side Request Forgery (SSRF) vulnerability in the ONLYOFFICE ownCloud Integration plugin version 9.12. The issue is in the /apps/onlyoffice/ajax/settings/address endpoint, which fails to properly validate the Document Server URL provided by users. An authenticated administrator can exploit this by sending a crafted URL to make the ownCloud server initiate outbound connections to arbitrary destinations, including internal systems or localhost.

Detection Guidance

To detect this SSRF vulnerability, monitor network traffic for outbound connections from the ownCloud server to unexpected or internal destinations. Check logs for requests to the /apps/onlyoffice/ajax/settings/address endpoint with manipulated document server parameters. Use tools like tcpdump or Wireshark to capture outbound HTTP requests originating from the ownCloud server.

Impact Analysis

An attacker with admin access could use this flaw to perform internal network reconnaissance or scan internal hosts by observing differences in server responses. This could expose sensitive internal services, enable further attacks, or allow the attacker to pivot within your network.

Compliance Impact

This vulnerability could lead to unauthorized access to internal systems, potentially violating data protection requirements under GDPR or HIPAA. Exposure of internal services may result in compliance breaches due to unauthorized data access or network reconnaissance activities.

Mitigation Strategies

Immediately update the ONLYOFFICE ownCloud Integration plugin to the latest version. Disable the plugin if an update is not available. Restrict network access to the ownCloud server to prevent unauthorized outbound connections. Review server logs for signs of exploitation and block suspicious IP addresses.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84282. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart