CRITICAL🇵🇱 Wersja polska

CVE-2023-26482

CVSS 9.0v3.1pub. 2023-03-30upd. 2024-11-21

Nextcloud server is an open source home cloud implementation. In affected versions a missing scope validation allowed users to create workflows which are designed to be only available for administrators. Some workflows are designed to be RCE by invoking defined scripts, in order to generate PDFs, invoking webhooks or running scripts on the server. Due to this combination depending on the available apps the issue can result in a RCE at the end. It is recommended that the Nextcloud Server is upgraded to 24.0.10 or 25.0.4. Users unable to upgrade should disable app `workflow_scripts` and `workflow_pdf_converter` as a mitigation.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
  • Nextcloud Server

    APP
    Nextcloud
    18.0.0 – 20.0.14.12 (excl.)21.0.0 – 21.0.9.10 (excl.)22.0.0 – 22.2.10.10 (excl.)23.0.0 – 23.0.12.5 (excl.)24.0.0 – 24.0.10 (excl.)25.0.0 – 25.0.4 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2021-32802CRITICAL9.3PL ✓same product

Nextcloud Server — SSRF, ujawnienie plików lub RCE przez podglądy obrazów

CVE-2021-22915CRITICAL9.8PL ✓same product

Nextcloud Server — obejście ochrony brute-force przez adresy IPv6

CVE-2026-45281HIGH8.1same product

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before...

CVE-2024-37313HIGH7.3same product

Nextcloud server is a self hosted personal cloud system. Under some circumstance it was possible to bypass the...

CVE-2024-37882HIGH8.1same product

Nextcloud Server is a self hosted personal cloud system. A recipient of a share with read&share permissions co...