---
id: CVE-2026-77166
title: >-
  The emoji field in the page emoji update endpoint does not properly validate
  user input
summary: >-
  The emoji field in the page emoji update endpoint does not properly validate
  user input. By injecting long text and line breaks, the sidebar layout becomes
  broken and can hide other items.
severity: low
cvss: 2.4
cvssVector: 'CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-840
vendor: Nextcloud
product: Collectives
affected:
  - Collectives >= 3.2.1 <= 3.5.0
published: '2026-09-21'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T19:17:10.840'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-77166'
references:
  - url: 'https://hackerone.com/reports/3599470'
    label: support@hackerone.com
  - url: 'https://hackerone.com/reports/3599470'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-21T18:42:53.420732Z'
ingestedAt: '2026-09-21T16:11:47.450Z'
---

## Overview

The emoji field in the page emoji update endpoint does not properly validate user input. By injecting long text and line breaks, the sidebar layout becomes broken and can hide other items.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
