CRITICAL
cbcoutinho
CVE published 2026-08-25
CVE-2026-55640
A critical vulnerability exists in Nextcloud MCP Server versions prior to 0.117.2, allowing unauthenticated network attackers to delete or trigger re-indexing of vector embeddings for any user and potentially destroy the semantic search index by sending forged deletion events. This issue arises from the POST /webhooks/nextcloud endpoint in nextcloud_mcp_server/vector/webhook_receiver.py having no authenti [truncated]