CRITICAL 9.1 CVE-2026-55640 Published 25 Aug 2026

Nextcloud MCP Server Unauthenticated Webhook Vulnerability

Worried this affects one of your servers?

Nextcloud MCP Server, a production-ready server connecting AI assistants to Nextcloud, is affected.

Prior to version 0.117.2, the POST /webhooks/nextcloud endpoint was vulnerable due to a lack of authentication by default.

An attacker could exploit this to delete or re-index vector embeddings and destroy the semantic search index for any user.

Reference: CVE-2026-55640 on NVD

← Back to Security News