Description
Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instance is established, and explicitly allows local/private addresses for this request, bypassing Nextcloud's core SSRF protections. The public, unauthenticated endpoints POST /apps/circles/event/ and POST /apps/circles/incoming/ reach this code path, allowing any unauthenticated user to force the server to issue a GET request to an internal address.

The response body of the internal request is never returned to the requester, so this is blind SSRF: an attacker can determine whether an internal service is reachable, but cannot read its response contents through this endpoint alone.
Published: 2026-09-18
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Blind SSRF allowing internal network discovery
Action: Assess Impact
AI Analysis

Impact

Circles’ remote‑instance signature verification performs a GET request to an attacker‑supplied keyId URL before authentication, and intentionally permits local or private addresses for this request. Public, unauthenticated endpoints POST /apps/circles/event/ and POST /apps/circles/incoming/ trigger this code path, giving any unauthenticated user the ability to cause the server to send a blind internal request. The response body is never returned, so the flaw provides only reconnaissance capability—an attacker can learn whether a service is reachable internally but cannot read its data directly.

Affected Systems

The vulnerability is present in Nextcloud Server, specifically within the Circles app. No specific version range is listed in the CNA data, so any deployed instance that includes this Circles functionality may be affected until fixed.

Risk and Exploitability

The CVSS score of 6.2 indicates moderate severity. The EPSS score of less than 1% and the absence from the CISA KEV catalog suggest a low probability of widespread exploitation at present, but the bug is accessible to anyone with network access to the public Nextcloud endpoints. An unauthenticated attacker can map the internal network topology by probing reachability of local addresses from the server, potentially aiding later attacks. The flaw requires no privileged client interaction and bypasses core SSRF protections, making it a straightforward blind SSRF vector.

Generated by OpenCVE AI on September 19, 2026 at 21:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any available Nextcloud Server patch that fixes the Circles remote‑instance verification flaw.
  • Disable the Circles remote‑instance feature or restrict it to a trusted domain by setting the appropriate configuration option to false.
  • Configure the server’s firewall or host rules to block outbound HTTP(S) requests to localhost or internal IP ranges from the Nextcloud process.
  • Continuously monitor logs for outbound GET requests originating from the app to internal addresses and investigate suspicious activity.

Generated by OpenCVE AI on September 19, 2026 at 21:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Sat, 19 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Blind SSRF in Nextcloud Circles via Remote-Instance Verification

Sat, 19 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Title Blind SSRF in Nextcloud Circles via Remote-Instance Verification

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Nextcloud
Nextcloud server
Vendors & Products Nextcloud
Nextcloud server

Fri, 18 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Description Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instance is established, and explicitly allows local/private addresses for this request, bypassing Nextcloud's core SSRF protections. The public, unauthenticated endpoints POST /apps/circles/event/ and POST /apps/circles/incoming/ reach this code path, allowing any unauthenticated user to force the server to issue a GET request to an internal address. The response body of the internal request is never returned to the requester, so this is blind SSRF: an attacker can determine whether an internal service is reachable, but cannot read its response contents through this endpoint alone.
Weaknesses CWE-918
References
Metrics cvssV3_0

{'score': 6.2, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Nextcloud Server
cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-09-18T19:41:07.400Z

Reserved: 2026-08-20T15:00:00.606Z

Link: CVE-2026-77164

cve-icon Vulnrichment

Updated: 2026-09-18T19:41:04.281Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T02:17:07.510

Modified: 2026-09-18T20:17:22.273

Link: CVE-2026-77164

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T21:45:16Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)