HIGH

CVE-2023-26482

CVSS v3

8.8

HIGH

EPSS Score

66.3%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Nextcloud server is an open source home cloud implementation. In affected versions a missing scope validation allowed users to create workflows which are designed to be only available for administrators. Some workflows are designed to be RCE by invoking defined scripts, in order to generate PDFs, invoking webhooks or running scripts on the server. Due to this combination depending on the available apps the issue can result in a RCE at the end. It is recommended that the Nextcloud Server is upgraded to 24.0.10 or 25.0.4. Users unable to upgrade should disable app `workflow_scripts` and `workflow_pdf_converter` as a mitigation.

Technical details

Published
3/30/2023

Frequently asked questions

What is CVE-2023-26482?

Nextcloud server is an open source home cloud implementation. In affected versions a missing scope validation allowed users to create workflows which are designed to be only available for administrators. Some workflows are designed to be RCE by invoking defined scripts, in order to generate PDFs, invoking webhooks or running scripts on the server. Due to this combination depending on the available apps the issue can result in a RCE at the end. It is recommended that the Nextcloud Server is upgraded to 24.0.10 or 25.0.4. Users unable to upgrade should disable app `workflow_scripts` and `workflow_pdf_converter` as a mitigation.

Is CVE-2023-26482 actively exploited?

Active exploitation of CVE-2023-26482 has not been confirmed. The EPSS score is 66.3%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2023-26482?

CVE-2023-26482 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2023-26482 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.