Executive brief
Nextcloud Deck is a Kanban-style task and project management application used by organizations to organize work and collaborate on projects. An authenticated user can modify board configuration settings for any board in the system without authorization checks, potentially allowing them to alter another user's board settings, disrupt workflows, or access sensitive board data.
Technical details
The Deck config API endpoint lacks proper authorization validation when setting board-scoped configuration keys. An authenticated attacker can specify arbitrary board IDs in API requests and modify configuration parameters without the system verifying the attacker's ownership or management permissions on the target board. The vulnerability requires authentication but allows an authenticated user to escalate privileges within the application by manipulating boards they do not own. Patches are expected from the Nextcloud security team.
Affected products
- Nextcloud Deck
Timeline
- 2026-09-18: disclosed
- other: CVE-2026-77170 assigned