WORLDTECH NEWS Global technology intelligence.Contact
← Back to WORLDTECH
Cybersecurity

VU#943094: ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerability

Small padlock on a network cable at a patch panelAI illustration
WORLDTECH illustration · AI-generated (Canva)

What happened

Differences in returned error messages (such as connection failures versus SSL/TLS negotiation errors) enable the attacker to distinguish between open and closed TCP ports, facilitating internal network reconnaissance and port enumeration. Disable or remove the plugin until a patched version is released.

Description The ownCloud ecosystem delivers a platform for enterprise file collaboration, providing capabilities for storing, syncing, and sharing data across devices. Ascensio System SIA's ONLYOFFICE provides a connector that integrates with ownCloud, enabling users to open and edit files directly within the cloud storage environment.

As detailed in CVE-2026-84282 , the application does not restrict or sanitize this parameter, allowing an authenticated administrator to provide arbitrary URLs, including internal network hosts or localhost addresses. Impact Successful exploitation allows an authenticated administrator to: * Trigger arbitrary outbound network requests from the ownCloud server (SSRF).

Key facts

  • Ascensio System SIA's ONLYOFFICE — provides: a connector that integrates with ownCloud, enabling users to open and edit files directly within the cloud storage environment

Sources & evidence