{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/nextcloud-hub--1.8.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:peering-manager:peering_manager:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":6.1,"id":"CVE-2024-28112"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Nextcloud Hub (\u003c 1.8.3)"],"_cs_severities":["low"],"_cs_tags":["web-application","vulnerability","rce"],"_cs_type":"advisory","_cs_vendors":["Nextcloud"],"content_html":"\u003cp\u003eNextcloud has released a security advisory addressing a remote code execution (RCE) vulnerability, identified as CVE-2024-28112. This flaw exists within the Nextcloud Hub software and stems from the improper handling of user-supplied input during request processing. An unauthenticated or remote attacker can leverage this vulnerability to inject and execute malicious code on the application server. This level of compromise grants the attacker the ability to read, modify, or delete sensitive data stored within the Nextcloud environment and potentially pivot into the wider network infrastructure. Given the critical nature of the vulnerability, organizations running Nextcloud Hub should prioritize patching their instances to the vendor-recommended version immediately.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2024-28112 allows an attacker to achieve full remote code execution on the server hosting Nextcloud. This provides the actor with unauthorized access to file stores, user credentials, and database contents, potentially leading to total system compromise and data exfiltration.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all internet-facing Nextcloud Hub instances and audit logs for anomalous POST requests or unexpected child processes spawned by the web server user.\u003c/li\u003e\n\u003cli\u003eApply the security update provided by Nextcloud to resolve CVE-2024-28112 immediately.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for requests containing suspicious payload patterns that could indicate attempted exploitation of the input handling flaw.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-17T13:09:29Z","date_published":"2026-09-17T13:09:29Z","id":"https://feed.craftedsignal.io/briefs/2026-09-nextcloud-rce/","summary":"A critical vulnerability in Nextcloud Hub, tracked as CVE-2024-28112, allows remote attackers to execute arbitrary code on the underlying application server.","title":"Remote Code Execution Vulnerability in Nextcloud","url":"https://feed.craftedsignal.io/briefs/2026-09-nextcloud-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Nextcloud Hub (\u003c 1.8.3)","version":"https://jsonfeed.org/version/1.1"}