← Back to CVE List
CVE-2026-77170NVD
Vulnerability Summary
The Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without validating whether the user owns or has permission to manage the referenced board.
CVSS v3.0 Base Metrics — Score 4.3 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeUnchanged
ConfidentialityNone
IntegrityLow
AvailabilityNone
Affected & Patched Versions
- Nextcloud Deck >= 1.16.0 and <= 1.18.0
- Nextcloud Deck 1.18.0