{"id":"CVE-2026-55640","summary":"Nextcloud MCP Server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default )","details":"Nextcloud MCP Server is a production-ready MCP server that connects AI assistants to a Nextcloud instance. Prior to 0.117.2, the POST /webhooks/nextcloud endpoint in nextcloud_mcp_server/vector/webhook_receiver.py has no authentication by default because WEBHOOK_SECRET defaults to None and startup validation does not require it. When WEBHOOK_SECRET is unset, handle_nextcloud_webhook() accepts unauthenticated requests. The payload[\"user\"][\"uid\"] field parsed in nextcloud_mcp_server/vector/webhook_parser.py is attacker-controlled and is used without an authenticated-session cross-check for Qdrant operations, allowing a network attacker to delete or trigger re-indexing of vector embeddings for any user and to destroy the semantic search index by sending forged deletion events. This issue is fixed in version 0.117.2.","aliases":["GHSA-8vh3-g2qg-2h2c"],"modified":"2026-08-27T11:47:40.690742307Z","published":"2026-08-25T16:03:28.085Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55640.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-306"]},"references":[{"type":"WEB","url":"https://github.com/cbcoutinho/nextcloud-mcp-server/tree/v0.117.2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55640.json"},{"type":"ADVISORY","url":"https://github.com/cbcoutinho/nextcloud-mcp-server/security/advisories/GHSA-8vh3-g2qg-2h2c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55640"},{"type":"FIX","url":"https://github.com/cbcoutinho/nextcloud-mcp-server/commit/4fc2b10945108cf1008ec9698291de6706ffcb73"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cbcoutinho/nextcloud-mcp-server","events":[{"introduced":"0"},{"fixed":"4fc2b10945108cf1008ec9698291de6706ffcb73"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"0.117.2"}]}}],"versions":["v0.117.1","v0.117.0","v0.116.0","v0.115.1","v0.115.0","v0.114.0","v0.113.1","v0.113.0","v0.112.0","v0.111.0","v0.110.2","v0.110.1","v0.110.0","v0.109.1","v0.109.0","v0.108.3","v0.108.2","v0.108.1","v0.108.0","v0.107.0","v0.106.0","v0.105.0","v0.104.1","v0.104.0","v0.103.0","v0.102.0","v0.101.4","v0.101.3","v0.101.2","v0.101.1","v0.101.0","v0.100.0","v0.99.0","v0.98.1","v0.98.0","v0.97.0","v0.96.0","v0.95.0","v0.94.1","v0.94.0","v0.93.0","v0.92.1","v0.92.0","v0.91.2","v0.91.3","v0.91.1","v0.91.0","v0.90.2","v0.90.1","v0.90.0","v0.88.3","v0.88.2","v0.88.1","v0.87.2","v0.88.0","v0.87.1","v0.87.0","v0.86.4","v0.86.3","v0.86.2","v0.86.1","v0.86.0","v0.85.1","v0.85.0","v0.84.2","v0.84.1","v0.84.0","v0.83.4","v0.83.3","v0.83.2","v0.83.1","v0.83.0","v0.82.0","v0.81.0","v0.80.0","v0.79.3","v0.79.2","v0.79.1","v0.79.0","v0.78.0","v0.77.1","v0.77.0","v0.76.0","v0.75.2","v0.75.1","v0.75.0","v0.74.0","v0.73.2","v0.73.1","v0.73.0","v0.72.7","v0.72.6","v0.72.5","v0.72.4","v0.72.3","v0.72.2","v0.72.1","v0.72.0","v0.71.0","v0.70.4","v0.70.3","v0.70.2","v0.70.1","v0.70.0","v0.69.0","v0.68.4","v0.68.3","v0.68.2","v0.68.1","v0.68.0","v0.67.0","v0.66.2","v0.66.1","v0.66.0","v0.65.4","v0.65.3","v0.65.2","v0.65.1","v0.65.0","v0.64.5","v0.64.4","v0.64.3","v0.64.2","v0.64.1","v0.64.0","v0.63.5","v0.63.4","v0.63.3","v0.63.2","v0.63.1","v0.63.0","v0.62.0","v0.61.5","v0.61.4","v0.61.3","v0.61.2","v0.61.1","v0.61.0","v0.60.3","v0.60.4","v0.60.2","v0.60.1","v0.60.0","v0.59.1","v0.59.0","v0.58.0","v0.57.0","v0.56.2","v0.56.1","v0.56.0","v0.55.1","v0.55.0","v0.54.0","v0.53.0","v0.52.1","v0.52.0","v0.51.0","v0.50.2","v0.50.1","v0.50.0","v0.49.2","v0.49.1","v0.49.0","v0.48.5","v0.48.4","v0.48.3","v0.48.2","v0.48.1","v0.48.0","v0.47.0","v0.46.2","v0.46.1","v0.46.0","v0.45.0","v0.44.1","v0.44.0","v0.43.0","v0.42.0","v0.41.0","v0.40.0","v0.39.0","v0.38.0","v0.36.0","v0.35.0","v0.34.2","v0.34.0","v0.33.1","v0.33.0","v0.32.1","v0.32.0","v0.31.1","v0.31.0","v0.30.0","v0.29.2","v0.29.1","v0.29.0","v0.28.0","v0.27.3","v0.27.2","v0.27.1","v0.27.0","v0.26.1","v0.26.0","v0.25.0","v0.24.0","v0.24.1","v0.23.0","v0.22.7","v0.22.6","v0.22.5","v0.22.4","v0.22.3","v0.22.2","v0.22.1","v0.22.0","v0.21.0","v0.20.0","v0.19.1","v0.19.0","v0.18.0","v0.17.1","v0.17.0","v0.16.0","v0.15.2","v0.15.1","v0.15.0","v0.14.3","v0.14.2","v0.14.1","v0.14.0","v0.13.0","v0.12.6","v0.12.5","v0.12.4","v0.12.3","v0.12.2","v0.12.1","v0.11.1","v0.11.0","v0.10.0","v0.9.0","v0.8.3","v0.8.2","v0.8.1","v0.8.0","v0.7.2","v0.7.1","v0.7.0","v0.6.1","v0.5.0","v0.4.1","v0.4.0","v0.3.0","v0.2.5","v0.2.4","v0.2.2","v0.2.1","v0.2.0","v0.1.3","v0.1.2","v0.1.1","v0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55640.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"}]}