VORANT. Threat Intelligence Sign in Get the full feed

SSRF flaw in ONLYOFFICE ownCloud plugin

routine vulnerability technology

An unpatched SSRF vulnerability in the ONLYOFFICE ownCloud integration plugin lets admins force the server to probe internal hosts and localhost services.

CERT/CC has published an advisory for CVE-2026-84282, a Server-Side Request Forgery vulnerability in Ascensio System SIA's ONLYOFFICE integration plugin for ownCloud (version 9.12). The plugin's document server configuration endpoint, /apps/onlyoffice/ajax/settings/address, fails to validate or restrict the supplied document server URL before the ownCloud backend initiates an outbound connection to it. An authenticated administrator can submit crafted configuration requests pointing to internal hosts or localhost (127.0.0.1), causing the ownCloud server to issue requests on the attacker's behalf.

Because the plugin returns different error messages depending on connection outcome (e.g., TCP connection failure versus SSL/TLS negotiation failure), an attacker can use these response differences as a side channel to enumerate open versus closed ports on internal systems, enabling network reconnaissance that would otherwise be blocked from external access. This effectively turns the ownCloud server into a proxy for internal scanning and could facilitate follow-on attacks against internal services discovered this way.

The vendor could not be reached to coordinate disclosure, so no patch is currently available. CERT/CC recommends disabling or removing the ONLYOFFICE plugin until a fix is released, and applying network-level egress controls to restrict outbound connections from the ownCloud server to authorized destinations only. Exploitation requires authenticated administrator access, which somewhat limits the attack surface, but organizations running affected ownCloud/ONLYOFFICE integrations should treat this as a priority to mitigate given the lack of vendor patch.

Mentioned in this report

Vulnerabilities CVE-2026-84282

Source reporting: https://kb.cert.org/vuls/id/943094

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free