CVE-2026-77166: Nextcloud Collectives
Low severity, CVSS 2.4. EPSS: 0.3% chance of exploitation in the next 30 days.
The emoji field in the page emoji update endpoint does not properly validate user input. By injecting long text and line breaks, the sidebar layout becomes broken and can hide other items.
Affected products
- Nextcloud Collectives: from 3.2.1, up to and including 3.5.0
Published 2026-09-21. Last modified 2026-09-22.