Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Nextcloud MCP Server unauthenticated webhook endpoint allows index deletion

Nextcloud MCP Server prior to 0.117.2 has an unauthenticated webhook endpoint that allows attackers to delete or re-index vector embeddings for any user by sending forged deletion events, due to missing authentication when WEBHOOK_SECRET is unset.

Disclosed 25 August 2026 · Record updated 13 September 2026

Impact

Network attackers can delete or trigger re-indexing of vector embeddings for any user and destroy the semantic search index when WEBHOOK_SECRET is not configured

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-55640