SB20260914101 - Fedora EPEL 10.2 update for nextcloud
Published: September 14, 2026 Updated: October 1, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 7 vulnerabilities.
1) Improper access control (CVE-ID: CVE-2026-66010)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary script code.
The vulnerability exists due to improper access control in the CUSTOM_ELEMENT_HANDLING sanitization logic when processing allowed custom elements. A remote attacker can supply specially crafted HTML content to execute arbitrary script code.
The bypass affects the afterSanitizeElements hook and the payload becomes executable only after a custom element writes sanitized data into innerHTML.
2) Improper access control (CVE-ID: CVE-2026-65903)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to bypass tag filtering restrictions.
The vulnerability exists due to improper access control in the ADD_TAGS tag handling logic when processing sanitized HTML with both ADD_TAGS as a function and FORBID_TAGS enabled. A remote user can supply crafted markup using forbidden tags to bypass tag filtering restrictions.
Only applications that use ADD_TAGS in function form together with FORBID_TAGS are affected.
3) Incorrect Behavior Order: Validate Before Canonicalize (CVE-ID: CVE-2026-59883)
CWE-ID: CWE-180 - Incorrect Behavior Order: Validate Before Canonicalize
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to noncanonical cookie domain keeps subdomain scope. A remote attacker can disclose session cookies to attacker-controlled subdomains or inject malicious cookies on the system.
4) Prototype pollution (CVE-ID: CVE-2026-67316)
CWE-ID: CWE-1321 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVSSv4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to alter request semantics.
The vulnerability exists due to improperly controlled modification of object prototype attributes in bodyless method aliases in lib/core/Axios.js when processing requests after Object.prototype has already been polluted. A remote user can pollute Object.prototype.data to alter request semantics.
Exploitation requires chaining with a separate prototype pollution condition in the same process.
5) Prototype pollution (CVE-ID: CVE-2026-71437)
CWE-ID: CWE-1321 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service or corrupt application logic.
The vulnerability exists due to improperly controlled modification of object prototype attributes ('prototype pollution') in the architecture-beta diagram renderer when rendering an untrusted diagram. A remote user can supply a crafted diagram with a group id of __proto__ to cause a denial of service or corrupt application logic.
The injected property value is limited to the string horizontal or vertical and does not directly enable remote code execution.
6) Prototype pollution (CVE-ID: CVE-2026-71438)
CWE-ID: CWE-1321 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to modify object prototypes.
The vulnerability exists due to improperly controlled modification of object prototype attributes in the mermaid configuration setters when merging caller-supplied configuration objects into the internal config. A local privileged user can supply a crafted configuration object to modify object prototypes.
The issue is only reachable if an application forwards attacker-controlled data directly into these configuration entry points; user-controlled configuration in diagram code and YAML frontmatter is already protected.
7) Cross-site scripting (CVE-ID: CVE-2026-65900)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote attacker to execute arbitrary script in the victim's browser.
The vulnerability exists due to improper neutralization of script-related template expressions in template content in DOMPurify SAFE_FOR_TEMPLATES handling when sanitizing content using the RETURN_DOM or IN_PLACE output modes. A remote attacker can supply specially crafted template content with split expression text nodes to execute arbitrary script in the victim's browser.
The issue is specific to template content that is later normalized or evaluated by a template engine, allowing split text nodes to merge into a fully formed expression after sanitization.
Remediation
Install update from vendor's website.