{"id":"CVE-2026-77166","title":"The emoji field in the page emoji update endpoint does not properly validate user input","summary":"The emoji field in the page emoji update endpoint does not properly validate user input. By injecting long text and line breaks, the sidebar layout becomes broken and can hide other items.","severity":"low","cvss":2.4,"cvssVector":"CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N","cwe":["CWE-840"],"vendor":"Nextcloud","product":"Collectives","affected":["Collectives >= 3.2.1 <= 3.5.0"],"published":"2026-09-21","updated":"2026-09-21","sourceUpdated":"2026-09-21T16:17:24.013","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-77166","references":[{"url":"https://hackerone.com/reports/3599470","label":"support@hackerone.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-21T16:11:47.450Z","slug":"CVE-2026-77166","body":"## Overview\n\nThe emoji field in the page emoji update endpoint does not properly validate user input. By injecting long text and line breaks, the sidebar layout becomes broken and can hide other items.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":13,"depthScoreParts":{"impact":13.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}