Junglewise Threat Intelligence

CVE-2026-77170: Nextcloud Deck authorization bypass in config API

CVE-2026-77170 · Severity: medium · CVSS 4.3 · Published 2026-09-18

Vendors: Nextcloud.

Executive brief

Nextcloud Deck is a Kanban-style task and project management application used by organizations to organize work and collaborate on projects. An authenticated user can modify board configuration settings for any board in the system without authorization checks, potentially allowing them to alter another user's board settings, disrupt workflows, or access sensitive board data.

Technical details

The Deck config API endpoint lacks proper authorization validation when setting board-scoped configuration keys. An authenticated attacker can specify arbitrary board IDs in API requests and modify configuration parameters without the system verifying the attacker's ownership or management permissions on the target board. The vulnerability requires authentication but allows an authenticated user to escalate privileges within the application by manipulating boards they do not own. Patches are expected from the Nextcloud security team.

Affected products

  • Nextcloud Deck

Timeline

  • 2026-09-18: disclosed
  • other: CVE-2026-77170 assigned

References