Skip to main content
Vulnerability Database/CVE-2026-77164

CVE-2026-77164: Nextcloud Circles SSRF Vulnerability

CVE-2026-77164 is a blind server-side request forgery vulnerability in Nextcloud Circles that allows unauthenticated attackers to probe internal networks. This article covers technical details, exploitation risks, and remediation.

Published:

CVE-2026-77164 Overview

CVE-2026-77164 is a Server-Side Request Forgery (SSRF) vulnerability [CWE-918] in the Nextcloud Circles application. The flaw resides in the remote-instance signature verification logic, which fetches an attacker-supplied keyId URL before establishing trust in the remote instance. The Circles code path explicitly permits local and private addresses, bypassing Nextcloud's core SSRF protections. Unauthenticated attackers can reach the vulnerable code through the public endpoints POST /apps/circles/event/ and POST /apps/circles/incoming/, forcing the server to issue GET requests to internal addresses.

Critical Impact

Unauthenticated blind SSRF allows attackers to probe internal network services from the Nextcloud server, enabling reconnaissance of otherwise unreachable infrastructure.

Affected Products

  • Nextcloud Circles application
  • Nextcloud server deployments with Circles enabled
  • Instances exposing POST /apps/circles/event/ and POST /apps/circles/incoming/ endpoints

Discovery Timeline

  • 2026-09-18 - CVE-2026-77164 published to NVD
  • 2026-09-18 - Last updated in NVD database

Technical Details for CVE-2026-77164

Vulnerability Analysis

The Circles application implements its own HTTP client logic for verifying signatures on federated requests between Nextcloud instances. When an inbound request arrives, Circles retrieves the signer's public key by fetching the URL supplied in the keyId parameter. This fetch happens before any trust decision about the remote instance is made.

Circles overrides Nextcloud's built-in SSRF safeguards by explicitly allowing requests to local and private IP ranges. The rationale supports federation between internal instances, but the effect eliminates the network-boundary defense that the core platform normally enforces. Because the response body is never returned to the requester, exploitation yields blind SSRF, meaning attackers can infer reachability and service state but cannot exfiltrate response content directly through this endpoint.

Root Cause

The root cause is trust ordering: Circles performs an outbound HTTP fetch based on attacker-controlled input before validating that the source is a trusted federated peer. Combined with the explicit allow-list for private address space, this violates the principle that unauthenticated input must never drive requests to internal-only destinations.

Attack Vector

An unauthenticated attacker sends a crafted POST request to /apps/circles/event/ or /apps/circles/incoming/ containing a signature header whose keyId points to an internal URL. The server issues a GET request against that URL as part of signature verification. Response timing and error behavior reveal whether the internal service is reachable, enabling internal port and service mapping from the Nextcloud host's network position.

No authentication, user interaction, or elevated privileges are required to reach the vulnerable endpoints. See the HackerOne Report #3303283 for the researcher's technical write-up.

Detection Methods for CVE-2026-77164

Indicators of Compromise

  • Unauthenticated POST requests to /apps/circles/event/ or /apps/circles/incoming/ from external IP addresses
  • Outbound HTTP GET requests from the Nextcloud server to RFC1918 addresses, loopback, or link-local ranges originating from the Circles app
  • Signature headers on inbound federation requests containing keyId values that resolve to internal hostnames or private IPs
  • Repeated federation requests from a single source enumerating varying internal targets

Detection Strategies

  • Inspect Nextcloud access logs for anomalous volumes of requests to Circles federation endpoints from untrusted networks
  • Correlate inbound Circles requests with outbound server-initiated HTTP traffic to internal destinations
  • Alert on any egress from the Nextcloud application process targeting metadata services or private subnets
  • Baseline legitimate federation partners and flag keyId values that fall outside the expected set

Monitoring Recommendations

  • Enable verbose logging on the Circles application and forward federation events to a centralized log platform
  • Monitor egress firewall logs for connections from the Nextcloud host to internal management interfaces
  • Track HTTP response codes and timing patterns on internal services that could indicate SSRF probing

How to Mitigate CVE-2026-77164

Immediate Actions Required

  • Upgrade the Circles application to the patched release published by Nextcloud as soon as it is available
  • Restrict network egress from the Nextcloud server to only the destinations required for legitimate federation
  • If Circles federation is not in use, disable the Circles application entirely
  • Place the Nextcloud server in a network segment that cannot reach sensitive internal management interfaces

Patch Information

Refer to the HackerOne Report #3303283 and the Nextcloud Circles project advisories for the fixed version. The corrective change must ensure that signature verification honors the platform SSRF policy and rejects keyId URLs resolving to private, loopback, or link-local addresses.

Workarounds

  • Block unauthenticated external access to /apps/circles/event/ and /apps/circles/incoming/ at the reverse proxy or web application firewall
  • Enforce egress filtering on the Nextcloud host to deny outbound connections to RFC1918, loopback, and cloud metadata address ranges
  • Require mutual TLS or IP allow-listing for federation traffic from known partner instances
bash
# Example nginx snippet to restrict Circles federation endpoints to known peers
location ~ ^/apps/circles/(event|incoming)/ {
    allow 203.0.113.10;   # trusted federation peer
    allow 198.51.100.20;  # trusted federation peer
    deny all;
    proxy_pass http://nextcloud_backend;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.