{"document":{"acknowledgments":[{"urls":["https://kb.cert.org/vuls/id/943094#acknowledgements"]}],"category":"CERT/CC Vulnerability Note","csaf_version":"2.0","notes":[{"category":"summary","text":"### Overview\r\nA Server-Side Request Forgery (SSRF) vulnerability exists in Ascensio System SIA's ONLYOFFICE ownCloud integration plugin (version 9.12). The plugin’s backend endpoint does not adequately validate the user‑supplied document server URL before initiating outbound connections. An authenticated administrator can exploit this flaw to coerce the ownCloud server into issuing arbitrary network requests to attacker‑controlled destinations.\r\n\r\n### Description\r\nThe ownCloud ecosystem delivers a platform for enterprise file collaboration, providing capabilities for storing, syncing, and sharing data across devices. Ascensio System SIA's ONLYOFFICE provides a connector that integrates with ownCloud, enabling users to open and edit files directly within the cloud storage environment.\r\n\r\nWhen configuring the ONLYOFFICE document server within ownCloud, the plugin accepts a document server parameter and attempts to verify the supplied URL by initiating a connection directly from the ownCloud server. As detailed in ***CVE-2026-84282***, the application does not restrict or sanitize this parameter, allowing an authenticated administrator to provide arbitrary URLs, including internal network hosts or localhost addresses. By submitting crafted configuration requests to the `/apps/onlyoffice/ajax/settings/address` endpoint, an attacker can instruct the server to make outbound requests to internal systems that are otherwise inaccessible externally. Differences in returned error messages (such as connection failures versus SSL/TLS negotiation errors) enable the attacker to distinguish between open and closed TCP ports, facilitating internal network reconnaissance and port enumeration. The outbound requests originate from the ownCloud server, demonstrating server‑side request execution consistent with an SSRF vulnerability. This vulnerability could allow an attacker to abuse the ownCloud server infrastructure as a proxy to send malicious content to targeted systems.\r\n\r\n### Impact\r\nSuccessful exploitation allows an authenticated administrator to:\r\n* Trigger arbitrary outbound network requests from the ownCloud server (SSRF).\r\n* Access and probe localhost services (127.0.0.1) not reachable externally.\r\n* Perform internal network reconnaissance and port scanning.\r\n* Identify open and closed TCP ports through response‑based side channels.\r\n* Increase the attack surface for potential follow‑on exploitation of internal services.\r\n\r\n### Solution\r\nUnfortunately, the vendor could not be reached to coordinate this vulnerability. While an official patch is not available at this time, there are a few general recommendations that may help mitigate this vulnerability. Disable or remove the plugin until a patched version is released. Network‑level egress controls should be applied to limit outbound connections from the ownCloud server to authorized destinations only. \r\n\r\n### Acknowledgements\r\nThank you to Nguyen Huy Hoang, Nguyen Vu Long and Nguyen Tien Dat of ETC JSC for reporting this vulnerability. This document was written by Bob Kemerer.","title":"Summary"},{"category":"legal_disclaimer","text":"THIS DOCUMENT IS PROVIDED ON AN 'AS IS' BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. ","title":"Legal Disclaimer"},{"category":"other","text":"CERT/CC Vulnerability Note is a limited advisory. It primarily identifies vendors impacted by the advisory and not specific products. We only support \"known_affected\" and \"known_not_affected\" status. Please consult the vendor's statements and advisory URL if provided by the vendor for more details ","title":"Limitations of Advisory"}],"publisher":{"category":"coordinator","contact_details":"Email: cert@cert.org, Phone: +1412 268 5800","issuing_authority":"CERT/CC under DHS/CISA https://www.cisa.gov/cybersecurity also see https://kb.cert.org/ ","name":"CERT/CC","namespace":"https://kb.cert.org/"},"references":[{"url":"https://certcc.github.io/certcc_disclosure_policy","summary":"CERT/CC vulnerability disclosure policy"},{"summary":"CERT/CC document released","category":"self","url":"https://kb.cert.org/vuls/id/943094"},{"url":"https://github.com/ONLYOFFICE/onlyoffice-owncloud/blob/master/controller/settingsapicontroller.php","summary":"https://github.com/ONLYOFFICE/onlyoffice-owncloud/blob/master/controller/settingsapicontroller.php"}],"title":"ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerability","tracking":{"current_release_date":"2026-09-08T14:23:49+00:00","generator":{"engine":{"name":"VINCE","version":"3.0.45"}},"id":"VU#943094","initial_release_date":"2026-09-08 14:23:49.451350+00:00","revision_history":[{"date":"2026-09-08T14:23:49+00:00","number":"1.20260908142349.1","summary":"Released on 2026-09-08T14:23:49+00:00"}],"status":"final","version":"1.20260908142349.1"}},"vulnerabilities":[{"title":"A Server-Side Request Forgery (SSRF) vulnerability exists in the ONLYOFFICE ownCloud Integration plugin version 9.","notes":[{"category":"summary","text":"A Server-Side Request Forgery (SSRF) vulnerability exists in the ONLYOFFICE ownCloud Integration plugin version 9.12. The /apps/onlyoffice/ajax/settings/address endpoint does not sufficiently validate the user-supplied Document Server URL before initiating outbound connections.\r\n\r\nAn authenticated administrator can manipulate the documentserver parameter to cause the ownCloud server to send arbitrary requests to attacker-controlled destinations, including localhost and internal network hosts. This allows internal network reconnaissance and TCP port scanning based on differences in server responses."}],"cve":"CVE-2026-84282","ids":[{"system_name":"CERT/CC V Identifier ","text":"VU#943094"}]}],"product_tree":{"branches":[]}}