CVE-2026-55640 | cbcoutinho nextcloud-mcp-server up to 0.117.1 Webhook Receiver webhook_receiver.py handle_nextcloud_webhook uid improper authentication
A vulnerability identified as critical has been detected in cbcoutinho nextcloud-mcp-server up to 0.117.1. This affects the function handle_nextcloud_webhook of the file nextcloud_mcp_server/vector/webhook_receiver.py of the component Webhook Receiver. The manipulation of the argument uid leads to improper authentication.
This vulnerability is uniquely identified as CVE-2026-55640. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.VulDB Recent EntriesRead More