Nextcloud MCP Server unauthenticated webhook endpoint allows index deletion
Nextcloud MCP Server prior to 0.117.2 has an unauthenticated webhook endpoint that allows attackers to delete or re-index vector embeddings for any user by sending forged deletion events, due to missing authentication when WEBHOOK_SECRET is unset.
Disclosed 25 August 2026 · Record updated 13 September 2026
Impact
Network attackers can delete or trigger re-indexing of vector embeddings for any user and destroy the semantic search index when WEBHOOK_SECRET is not configured
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-55640
