VU#943094: ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerability
A Server-Side Request Forgery (SSRF) vulnerability exists in the ONLYOFFICE ownCloud Integration plugin version 9.12. The /apps/onlyoffice/ajax/settings/address endpoint does not sufficiently validate the user-supplied Document Server URL before initiating outbound connections. An authenticated administrator can manipulate the document server parameter to cause the ownCloud server to send arbitrary requests to attacker-controlled destinations, including localhost and internal network hosts. This allows internal network reconnaissance and TCP port scanning based on differences in server responses.
AI Analysis
Technical Summary
The ONLYOFFICE ownCloud integration plugin (version 9.12) contains an SSRF vulnerability due to insufficient validation of the document server URL parameter. An authenticated administrator can submit crafted requests to the /apps/onlyoffice/ajax/settings/address endpoint, causing the ownCloud server to make arbitrary outbound connections, including to internal network hosts and localhost. Differences in error responses enable the attacker to perform internal port scanning and network reconnaissance. This SSRF could be abused to proxy malicious content to internal systems. No official patch or vendor statement is available at this time.
Potential Impact
Exploitation requires authenticated administrator access. Successful exploitation allows triggering arbitrary outbound network requests from the ownCloud server, including to internal and localhost services. This enables internal network reconnaissance, port scanning, and identification of open or closed TCP ports. The vulnerability increases the attack surface for potential follow-on attacks against internal services by abusing the ownCloud server as a proxy.
Mitigation Recommendations
No official patch or fix is currently available. It is recommended to disable or remove the ONLYOFFICE ownCloud integration plugin until a patched version is released. Additionally, network-level egress controls should be implemented to restrict outbound connections from the ownCloud server to authorized destinations only.
VU#943094: ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerability
Description
A Server-Side Request Forgery (SSRF) vulnerability exists in the ONLYOFFICE ownCloud Integration plugin version 9.12. The /apps/onlyoffice/ajax/settings/address endpoint does not sufficiently validate the user-supplied Document Server URL before initiating outbound connections. An authenticated administrator can manipulate the document server parameter to cause the ownCloud server to send arbitrary requests to attacker-controlled destinations, including localhost and internal network hosts. This allows internal network reconnaissance and TCP port scanning based on differences in server responses.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The ONLYOFFICE ownCloud integration plugin (version 9.12) contains an SSRF vulnerability due to insufficient validation of the document server URL parameter. An authenticated administrator can submit crafted requests to the /apps/onlyoffice/ajax/settings/address endpoint, causing the ownCloud server to make arbitrary outbound connections, including to internal network hosts and localhost. Differences in error responses enable the attacker to perform internal port scanning and network reconnaissance. This SSRF could be abused to proxy malicious content to internal systems. No official patch or vendor statement is available at this time.
Potential Impact
Exploitation requires authenticated administrator access. Successful exploitation allows triggering arbitrary outbound network requests from the ownCloud server, including to internal and localhost services. This enables internal network reconnaissance, port scanning, and identification of open or closed TCP ports. The vulnerability increases the attack surface for potential follow-on attacks against internal services by abusing the ownCloud server as a proxy.
Mitigation Recommendations
No official patch or fix is currently available. It is recommended to disable or remove the ONLYOFFICE ownCloud integration plugin until a patched version is released. Additionally, network-level egress controls should be implemented to restrict outbound connections from the ownCloud server to authorized destinations only.
Technical Details
- Classification
- {"confidence":0.95,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://kb.cert.org/vuls/id/943094","fetched":true,"fetchedAt":"2026-09-08T14:28:25.664Z","wordCount":607}
Threat ID: 6aa01b89acd9273b49c4d1f1
Added to database: 09/08/2026, 14:28:25 UTC
Last enriched: 09/08/2026, 14:28:30 UTC
Last updated: 09/08/2026, 19:40:10 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.