CriticalCERT/CCSep 08, 2026

VU#943094: ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerability

Overview A Server-Side Request Forgery (SSRF) vulnerability exists in Ascensio System SIA's ONLYOFFICE ownCloud integration plugin (version 9.12). The plugin’s backend endpoint does not adequately validate the user‑supplied document server URL before initiating outbound connections. An authenticated administrator can exploit this flaw to coerce the ownCloud server into issuing arbitrary network requests to attacker‑controlled destinations. Description The ownCloud ecosystem delivers a platform for enterprise file collaboration, providing capabilities for storing, syncing, and sharing data across devices. Ascensio System SIA's ONLYOFFICE provides a connector that integrates with ownCloud, ena

Why it matters

The weakness can enable direct compromise with limited attacker prerequisites, making internet-facing assets the first place to look.

What defenders should do

Identify affected versions, prioritize internet-facing systems, and apply the vendor remediation.

Verify at the source

CyberKit curates and prioritizes; the source remains authoritative. Read the original advisory at kb.cert.org →

Need to validate an indicator or network range?
Move from reading to action with the free CyberKit toolbox.
Use security tools