← Vulnerability feed

Vulnerability record · CVE-2022-31014 · published 5 July 2022

CVE-2022-31014: Nextcloud server injection vulnerability

Nextcloud · Nextcloud Server

Nextcloud server is an open source personal cloud server. Affected versions were found to be vulnerable to SMTP command injection. The impact varies based on which commands are supported by the backend SMTP server. However, the main risk here is that the attacker can then hijack an already-authenticated SMTP session and run arbitrary SMTP commands as the email user, such as sending emails to other users, changing the FROM user, and so on. As before, this depends on the configuration of the server itself, but newlines should be sanitized to mitigate such arbitrary SMTP command injection. It is recommended that the Nextcloud Server is upgraded to 22.2.8 , 23.0.5 or 24.0.1. There are no known workarounds for this issue.

3.5 CVSS 3.1 Low EPSS 2.5% · top 15.8% CWE-74 · InjectionCWE-93 · CWE-93
3.5CVSS 3.1 base score, v2 3.5
2.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Nextcloud server is an open source personal cloud server. Affected versions were found to be vulnerable to SMTP command injection. The impact varies based on which commands are supported by the backend SMTP server. However, the main risk here is that the attacker can then hijack an already-authenticated SMTP session and run arbitrary SMTP commands as the email user, such as sending emails to other users, changing the FROM user, and so on. As before, this depends on the configuration of the server itself, but newlines should be sanitized to mitigate such arbitrary SMTP command injection. It is recommended that the Nextcloud Server is upgraded to 22.2.8 , 23.0.5 or 24.0.1. There are no known workarounds for this issue.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-264h-3v4w-6xh2 ExploitThird Party Advisory
https://github.com/nextcloud/server/pull/32428 Issue TrackingPatchThird Party Advisory
https://hackerone.com/reports/1516377 ExploitIssue TrackingPatchThird Party Advisory
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-264h-3v4w-6xh2 ExploitThird Party Advisory
https://github.com/nextcloud/server/pull/32428 Issue TrackingPatchThird Party Advisory
https://hackerone.com/reports/1516377 ExploitIssue TrackingPatchThird Party Advisory

Track CVE-2022-31014 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-49792Nextcloud server improper restriction of authentication attempts vulnerabilityNextcloud Server provides data storage for Nextcloud, an open source cloud platform. In Nextcloud Server prior to versions 26.0.9 and 27.1.4; as well…EPSS 1.0%9.8CVE-2023-48306Nextcloud server server-side request forgery (ssrf) vulnerabilityNextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.11, 26.0.6…EPSS 0.80%9.8CVE-2021-32802Nextcloud server inclusion from untrusted sphere vulnerabilityNextcloud server is an open source, self hosted personal cloud. Nextcloud supports rendering image previews for user provided file content. For some …EPSS 2.6%9.8CVE-2021-32726Nextcloud server improper authentication vulnerabilityNextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, webauthn tokens were not deleted…EPSS 1.8%9.8CVE-2021-22915Nextcloud server improper restriction of authentication attempts vulnerabilityNextcloud server before 19.0.11, 20.0.10, 21.0.2 is vulnerable to brute force attacks due to lack of inclusion of IPv6 subnets in rate-limiting consi…EPSS 1.7%9.1CVE-2023-35172Nextcloud server improper restriction of authentication attempts vulnerabilityNextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform. In NextCloud Server version…EPSS 0.92%9.1CVE-2021-32654Nextcloud server insecure direct object reference vulnerabilityNextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.11, 20.0.10, and 21.0.2, an attacker is able to receive …EPSS 1.8%8.8CVE-2023-45151Nextcloud server cleartext storage of sensitive data vulnerabilityNextcloud server is an open source home cloud platform. Affected versions of Nextcloud stored OAuth2 tokens in plaintext which allows an attacker who…EPSS 0.48%

Source: NIST National Vulnerability Database (record CVE-2022-31014), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.