ONLYOFFICE SSRF advisory: restrict administrative egress
Read CERT/CC VU#943094 with its administrator prerequisite, affected connector and containment options.
Contents of this article
Preserve the advisory’s prerequisites
CERT/CC published VU#943094 on September 8, 2026 for CVE-2026-84282 in ONLYOFFICE’s ownCloud connector 9.12. The described attacker is an authenticated administrator influencing outbound requests through document-server configuration, not an arbitrary anonymous visitor.
Map the connector’s outbound access
Inventory the instance, connector version, document server and authorized administrators. Review whether the collaboration server can reach databases, management services or cloud metadata. Administrative access should not implicitly authorize arbitrary internal network access.
Date the remediation status
The September 8 note states that an official patch was not then available and recommends disabling or removing the plugin and restricting egress. Recheck subsequent vendor releases; this dated status is not a permanent claim. Communicate any disruption to editing workflows.
Test permitted and denied paths
Test that the approved document server works and unauthorized destinations, including redirected targets, are denied. Preserve change and egress records and retest preview, editing and saving. An inbound WAF does not define the application’s internal network permissions.
