PoC Archive PoC Archive

tag

Webdav

  • CVE-2026-41179 web CRITICAL 9.8

    rclone RC API Unauthenticated Remote Code Execution (CVE-2026-41179)

    rclone's built-in Remote Control (rcd) HTTP API exposes an /operations/fsinfo endpoint that accepts an attacker-controlled fs= connection-string parameter used to instantiate a storage backend. When the string selects the WebDAV backend, rclone recognizes an…

    Patched 2026-07-05
  • None assigned as of 2026-07-03 cloud HIGH

    Nextcloud Federated Share OCM Bearer Token Scope Escalation to Sender WebDAV Access

    When a Nextcloud user creates a normal federated file share, the sender instance generates a permanent authentication token that is also stored as the federated share's secret; that token is created without an explicit narrow scope, so it defaults to full…

    Unverified 2026-07-03