Description
The emoji field in the page emoji update endpoint does not properly validate user input. By injecting long text and line breaks, the sidebar layout becomes broken and can hide other items.
Published: 2026-09-21
Score: 2.4 Low
EPSS: < 1% Very Low
KEV: No
Impact: UI degradation through layout breakage
Action: Apply Patch
AI Analysis

Impact

The vulnerability arises because the emoji field in the page emoji update endpoint does not enforce proper input validation. By sending a payload comprising long text and line breaks, an attacker can corrupt the sidebar layout, causing visual elements to move or become hidden. This flaw falls under an input validation weakness (CWE‑840). While it does not lead to data loss or unauthorized access, the resulting UI disruption can affect user experience and potentially conceal critical interface components.

Affected Systems

The flaw affects the Nextcloud Collectives app. No specific version numbers are provided in the data, so any installation of Collectives running the affected endpoint without the proper validation fix is at risk.

Risk and Exploitability

The CVSS score of 2.4 indicates low severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited exploitation activity so far. The attack vector is likely remote via authenticated web requests to the emoji update endpoint. An attacker with write access to emojis could use this to cause UI distortion for other users, but the impact remains modest and primarily cosmetic.

Generated by OpenCVE AI on September 21, 2026 at 16:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to the latest Nextcloud Collectives release that implements proper input validation for the emoji field
  • If the emoji update feature is unnecessary for your environment, disable or remove the endpoint to eliminate the attack surface
  • Monitor use logs for excessive or abnormal emoji update requests and verify that the sidebar layout remains intact for end users

Generated by OpenCVE AI on September 21, 2026 at 16:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Title Inadequate Input Validation in Emoji Update Endpoint Causes Layout Breakage

Mon, 21 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Nextcloud
Nextcloud collectives
Vendors & Products Nextcloud
Nextcloud collectives

Mon, 21 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description The emoji field in the page emoji update endpoint does not properly validate user input. By injecting long text and line breaks, the sidebar layout becomes broken and can hide other items.
Weaknesses CWE-840
References
Metrics cvssV3_0

{'score': 2.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Nextcloud Collectives
cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-09-21T18:43:30.904Z

Reserved: 2026-08-20T15:00:00.606Z

Link: CVE-2026-77166

cve-icon Vulnrichment

Updated: 2026-09-21T18:43:24.375Z

cve-icon NVD

Status : Deferred

Published: 2026-09-21T16:17:24.013

Modified: 2026-09-22T20:00:03.713

Link: CVE-2026-77166

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T17:00:09Z

Weaknesses