Description
The Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without validating whether the user owns or has permission to manage the referenced board.
Published: 2026-09-18
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized configuration modification
Action: Assess Impact
AI Analysis

Impact

The Deck configuration API accepts changes to board‑scoped settings without verifying that the caller owns or has permission to manage the targeted board. An authenticated user can therefore alter settings for any board to which they otherwise lack access, potentially affecting the visibility, behavior or data access of other users. This flaw can degrade board integrity and create a covert channel for further misuse.

Affected Systems

Nextcloud Deck is affected. The vulnerability exists in any deployed instance that exposes the public Deck configuration API and has not applied the vendor’s ownership‑validation fix. No specific product versions are listed in the available data.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, and the EPSS score of <1% suggests a low probability of exploitation in the wild. The vulnerability is not currently listed in the CISA KEV catalog. Attackers must be authenticated to the system and rely on the API’s lack of access checks; no privilege escalation beyond existing credentials is required.

Generated by OpenCVE AI on September 19, 2026 at 21:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor’s patch or upgrade Nextcloud Deck to a version that validates board ownership before accepting configuration changes.
  • Restrict API access by ensuring that only board owners or administrators can call the configuration endpoint.
  • Verify that authentication tokens used for the API have the minimal privileges needed for the intended action.

Generated by OpenCVE AI on September 19, 2026 at 21:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Sat, 19 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Deck API Allows Unauthorized Configuration Changes to Boards

Sat, 19 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Title Deck API Allows Unauthorized Configuration Changes to Boards

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Nextcloud
Nextcloud deck
Vendors & Products Nextcloud
Nextcloud deck

Fri, 18 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Description The Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without validating whether the user owns or has permission to manage the referenced board.
Weaknesses CWE-284
References
Metrics cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-09-18T19:41:31.474Z

Reserved: 2026-08-20T15:00:00.606Z

Link: CVE-2026-77170

cve-icon Vulnrichment

Updated: 2026-09-18T19:41:27.000Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T02:17:07.783

Modified: 2026-09-18T20:17:22.493

Link: CVE-2026-77170

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T21:45:16Z

Weaknesses