A critical ONLYOFFICE ownCloud plugin SSRF vulnerability allows authenticated administrators to force arbitrary network requests. This flaw affects version 9.12 of the integration plugin. Currently, no public exploitation or proof-of-concept code has been confirmed.
- CVE: CVE-2026-84282
- CVSS: Awaiting analysis
- Product: Ascensio System SIA / OnlyOffice ONLYOFFICE ownCloud integration plugin
- Affected: 9.12
- Impact: A Server-Side Request Forgery (SSRF) vulnerability exists in the ONLYOFFICE ownCloud Integration plugin (version 9.12)
- Status: No confirmed exploitation yet
- Action: See vendor advisory
Why This Matters
The ownCloud platform provides enterprise file collaboration for many organizations worldwide. By exploiting this ONLYOFFICE ownCloud plugin SSRF flaw, an attacker gains unauthorized access to internal network hosts. Consequently, they can probe services that remain completely hidden from the public internet. This internal network reconnaissance greatly increases the attack surface. Furthermore, the attacker could use the ownCloud server as a proxy to launch secondary attacks against internal systems.
How the Attack Works
When administrators configure the document server, the application accepts a custom URL. As CERT/CC notes, “The plugin’s backend endpoint does not adequately validate the user-supplied document server URL before initiating outbound connections.” Therefore, an attacker can submit crafted requests to the /apps/onlyoffice/ajax/settings/address endpoint. The server then executes outbound connections to these supplied addresses. Moreover, the attacker analyzes the resulting error messages. As the advisory explains, “Differences in returned error messages… enable the attacker to distinguish between open and closed TCP ports.” This mechanism directly facilitates internal port scanning.
Affected Versions
This Server-Side Request Forgery vulnerability specifically affects Ascensio System SIA’s ONLYOFFICE ownCloud integration plugin version 9.12. Exact installation counts remain unavailable. However, ownCloud has a vast user base in the enterprise sector.
Patch and Mitigation Steps
Currently, Ascensio System SIA has not released an official patch. In addition, the vendor remains unreachable regarding this coordination. Until an update arrives, administrators should immediately disable or remove the ONLYOFFICE integration plugin. Finally, security teams must implement strict network-level egress controls. These rules will restrict outbound connections from the ownCloud server to trusted destinations only.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!