Impact
The Deck configuration API accepts changes to board‑scoped settings without verifying that the caller owns or has permission to manage the targeted board. An authenticated user can therefore alter settings for any board to which they otherwise lack access, potentially affecting the visibility, behavior or data access of other users. This flaw can degrade board integrity and create a covert channel for further misuse.
Affected Systems
Nextcloud Deck is affected. The vulnerability exists in any deployed instance that exposes the public Deck configuration API and has not applied the vendor’s ownership‑validation fix. No specific product versions are listed in the available data.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score of <1% suggests a low probability of exploitation in the wild. The vulnerability is not currently listed in the CISA KEV catalog. Attackers must be authenticated to the system and rely on the API’s lack of access checks; no privilege escalation beyond existing credentials is required.
OpenCVE Enrichment