CVE-2026-77170 PUBLISHED

Assigner: hackerone
Reserved: 20.08.2026 Published: 18.09.2026 Updated: 18.09.2026

The Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without validating whether the user owns or has permission to manage the referenced board.

Metrics

CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS Score: 4.3

Product Status

Vendor Nextcloud
Product Deck
Versions Default: unaffected
  • affected from 1.16.0 to 1.18.0 (incl.)

Credits

  • Dang Hung Vi (vidang04) finder

References

Problem Types

  • CWE-284 Improper Access Control - Generic CWE