CVE-2026-77166 PUBLISHED

Assigner: hackerone
Reserved: 20.08.2026 Published: 21.09.2026 Updated: 21.09.2026

The emoji field in the page emoji update endpoint does not properly validate user input. By injecting long text and line breaks, the sidebar layout becomes broken and can hide other items.

Metrics

CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
CVSS Score: 2.4

Product Status

Vendor Nextcloud
Product Collectives
Versions Default: unaffected
  • affected from 3.2.1 to 3.5.0 (incl.)

Credits

  • _dha (yoyomiski) finder

References

Problem Types

  • CWE-840 Business Logic Errors CWE