{"apiVersion":"1.0","identifier":"CVE-2026-55640","description":"Nextcloud MCP Server is a production-ready MCP server that connects AI assistants to a Nextcloud instance. Prior to 0.117.2, the POST /webhooks/nextcloud endpoint in nextcloud_mcp_server/vector/webhook_receiver.py has no authentication by default because WEBHOOK_SECRET defaults to None and startup validation does not require it. When WEBHOOK_SECRET is unset, handle_nextcloud_webhook() accepts unauthenticated requests. The payload[-user-][-uid-] field parsed in nextcloud_mcp_server/vector/webhook_parser.py is attacker-controlled and is used without an authenticated-session cross-check for Qdrant operations, allowing a network attacker to delete or trigger re-indexing of vector embeddings for any user and to destroy the semantic search index by sending forged deletion events. This issue is fixed in version 0.117.2.","publishedAt":"2026-08-25T16:16:55","lastModifiedAt":"2026-08-25T20:16:57","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-55640","cvssScore":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","epssProbability":0.00484,"riskScore":0.95,"affectedProduct":"nextcloud-mcp-server","affectedVersions":"<0.117.2","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-55640","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-55640","en":"https://www.redsauce.net/en/cves/CVE-2026-55640","fr":"https://www.redsauce.net/fr/cves/CVE-2026-55640","pt":"https://www.redsauce.net/pt/cves/CVE-2026-55640","de":"https://www.redsauce.net/de/cves/CVE-2026-55640","sk":"https://www.redsauce.net/sk/cves/CVE-2026-55640","el":"https://www.redsauce.net/el/cves/CVE-2026-55640"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-55640"}}