{"id":"CVE-2026-77170","title":"The Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without validating whether the user owns or has permission to manage the referenced board.","summary":"The Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without validating whether the user owns or has permission to manage the referenced board.","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","cwe":["CWE-284"],"vendor":"Nextcloud","product":"Deck","affected":["Deck >= 1.16.0 <= 1.18.0"],"published":"2026-09-18","updated":"2026-09-18","sourceUpdated":"2026-09-18T20:17:22.493","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-77170","references":[{"url":"https://hackerone.com/reports/3599383","label":"support@hackerone.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-18T19:41:21.226672Z"},"epss":0.00153,"epssPercentile":0.04804,"ingestedAt":"2026-09-18T01:33:24.270Z","slug":"CVE-2026-77170","body":"## Overview\n\nThe Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without validating whether the user owns or has permission to manage the referenced board.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}