Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instance is established, and explicitly allows local/private addresses for this request, bypassing Nextcloud's core SSRF protections. The public,
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-77169 | Nextcloud团队文件夹应用权限绕过漏洞 | |
| CVE-2026-77170 | Deck配置API越权设置任意看板配置漏洞 | |
| CVE-2026-82982 | CVE-2026-82982 | |
| CVE-2026-82980 | CVE-2026-82980 | |
| CVE-2026-82985 | CVE-2026-82985 | |
| CVE-2026-68493 | CVE-2026-68493 |
No comments yet