CRITICAL
9.1 CVE-2026-55640 Published 25 Aug 2026
Nextcloud MCP Server Unauthenticated Webhook Vulnerability
Worried this affects one of your servers?
Nextcloud MCP Server, a production-ready server connecting AI assistants to Nextcloud, is affected.
Prior to version 0.117.2, the POST /webhooks/nextcloud endpoint was vulnerable due to a lack of authentication by default.
An attacker could exploit this to delete or re-index vector embeddings and destroy the semantic search index for any user.
Reference: CVE-2026-55640 on NVD
← Back to Security News