CVE-2026-77170: Nextcloud Deck

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without validating whether the user owns or has permission to manage the referenced board.

Affected products

  • Nextcloud Deck: from 1.16.0, up to and including 1.18.0

Published 2026-09-18. Last modified 2026-09-18.