Auth Bypass: Deck Config API Allows Arbitrary Board ID Updates (CVE-2026-77170)
CVE-2026-77170 Published on September 18, 2026
The Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without validating whether the user owns or has permission to manage the referenced board.
Weakness Type
What is an Authorization Vulnerability?
The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVE-2026-77170 has been classified to as an Authorization vulnerability or weakness.
Products Associated with CVE-2026-77170
Want to know whenever a new CVE is published for Nextcloud Deck? stack.watch will email you.
Affected Versions
Nextcloud Deck:- Version 1.16.0, <= 1.18.0 is affected.