Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

VU#943094: ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerability

0
High
Published: 09/08/2026 (09/08/2026, 14:27:08 UTC)
Source: CERT/CC

Description

A Server-Side Request Forgery (SSRF) vulnerability exists in the ONLYOFFICE ownCloud Integration plugin version 9.12. The /apps/onlyoffice/ajax/settings/address endpoint does not sufficiently validate the user-supplied Document Server URL before initiating outbound connections. An authenticated administrator can manipulate the document server parameter to cause the ownCloud server to send arbitrary requests to attacker-controlled destinations, including localhost and internal network hosts. This allows internal network reconnaissance and TCP port scanning based on differences in server responses.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/08/2026, 14:28:30 UTC

Technical Analysis

The ONLYOFFICE ownCloud integration plugin (version 9.12) contains an SSRF vulnerability due to insufficient validation of the document server URL parameter. An authenticated administrator can submit crafted requests to the /apps/onlyoffice/ajax/settings/address endpoint, causing the ownCloud server to make arbitrary outbound connections, including to internal network hosts and localhost. Differences in error responses enable the attacker to perform internal port scanning and network reconnaissance. This SSRF could be abused to proxy malicious content to internal systems. No official patch or vendor statement is available at this time.

Potential Impact

Exploitation requires authenticated administrator access. Successful exploitation allows triggering arbitrary outbound network requests from the ownCloud server, including to internal and localhost services. This enables internal network reconnaissance, port scanning, and identification of open or closed TCP ports. The vulnerability increases the attack surface for potential follow-on attacks against internal services by abusing the ownCloud server as a proxy.

Mitigation Recommendations

No official patch or fix is currently available. It is recommended to disable or remove the ONLYOFFICE ownCloud integration plugin until a patched version is released. Additionally, network-level egress controls should be implemented to restrict outbound connections from the ownCloud server to authorized destinations only.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.95,"severitySource":"heuristic","classifier":"rss-v2"}
Article Source
{"url":"https://kb.cert.org/vuls/id/943094","fetched":true,"fetchedAt":"2026-09-08T14:28:25.664Z","wordCount":607}

Threat ID: 6aa01b89acd9273b49c4d1f1

Added to database: 09/08/2026, 14:28:25 UTC

Last enriched: 09/08/2026, 14:28:30 UTC

Last updated: 09/08/2026, 19:40:10 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses