CVE-2023-26482 is a critical vulnerability affecting Nextcloud Server versions prior to 24.0.10 and 25.0.4. It stems from a missing scope validation in Nextcloud's workflow functionality, allowing standard users to create administrator-only workflows. Depending on installed applications, this flaw can lead to Remote Code Execution (RCE) by invoking scripts, generating PDFs, or triggering webhooks. Rated with a CVSS score of 8.8 (High), this vulnerability is easily exploitable over the network with low privileges and no user interaction, resulting in high impacts to confidentiality, integrity, and availability. The EPSS score and FAUCET Risk Score indicate a significant likelihood of exploitation. While not currently listed in CISA's KEV catalog, a Metasploit module for this RCE is publicly available, confirming exploitability. The vulnerability has garnered substantial community attention with 11 mentions and some media coverage, suggesting active discussion and potential for widespread exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 18.0.0, < 20.0.14.12CPE matchmatch criteria | cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:* | ||
>= 21.0.0, < 21.0.9.10CPE matchmatch criteria | cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:* | ||
>= 22.0.0, < 22.2.10.10CPE matchmatch criteria | cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:* | ||
>= 23.0.0, < 23.0.12.5CPE matchmatch criteria | cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:* | ||
>= 24.0.0, < 24.0.10CPE matchmatch criteria | cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.