ONLYOFFICE SSRF advisory: restrict administrative egress

Read CERT/CC VU#943094 with its administrator prerequisite, affected connector and containment options.

Contents of this article

Preserve the advisory’s prerequisites

CERT/CC published VU#943094 on September 8, 2026 for CVE-2026-84282 in ONLYOFFICE’s ownCloud connector 9.12. The described attacker is an authenticated administrator influencing outbound requests through document-server configuration, not an arbitrary anonymous visitor.

Map the connector’s outbound access

Inventory the instance, connector version, document server and authorized administrators. Review whether the collaboration server can reach databases, management services or cloud metadata. Administrative access should not implicitly authorize arbitrary internal network access.

Date the remediation status

The September 8 note states that an official patch was not then available and recommends disabling or removing the plugin and restricting egress. Recheck subsequent vendor releases; this dated status is not a permanent claim. Communicate any disruption to editing workflows.

Test permitted and denied paths

Test that the approved document server works and unauthorized destinations, including redirected targets, are denied. Preserve change and egress records and retest preview, editing and saving. An inbound WAF does not define the application’s internal network permissions.

References

CERT/CC VU#943094

Continue reading

Read related content

Back to industry insights Contact technical support