← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 8, 2026 · 14:23via CERT/CC Vulnerability Notes

VU#943094: ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerability

Brief

Overview

A Server-Side Request Forgery (SSRF) vulnerability exists in Ascensio System SIA's ONLYOFFICE ownCloud integration plugin (version 9. 12). The plugin’s backend endpoint does not adequately validate the user‑supplied document server URL before initiating outbound connections.

An authenticated administrator can exploit this flaw to coerce the ownCloud server into issuing arbitrary network requests to attacker‑controlled destinations.

Description

The ownCloud ecosystem delivers a platform for enterprise file collaboration, providing capabilities for storing, syncing, and sharing data across devices. Ascensio System SIA's ONLYOFFICE provides a connector that integrates with ownCloud, enabling users to open and edit files directly within the cloud storage environment.

Read more on CERT/CC Vulnerability Notes