Ce mail provient de l'extérieur, restons vigilants ===================================================================== CERT-Renater Note d'Information No. 2026/VULN909 _____________________________________________________________________ DATE : 17/09/2026 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S): Systems running Server (Nextcloud) versions prior to 32.0.13, 33.0.7, 34.0.2, Server (Nextcloud Enterprise) versions prior to 22.2.10.42, 23.0.12.38, 24.0.13.37, 25.0.13.32, 26.0.13.29, 27.1.11.29, 28.0.14.20, 29.0.16.19, 30.0.17.12, 31.0.14.8, 32.0.13, 33.0.7, 34.0.2. ===================================================================== https://github.com/nextcloud/security-advisories/security/advisories/GHSA-7hwf-8pcj-33h4 _____________________________________________________________________ ImageMagick vulnerability abusable via previews of malicious files High DorraJaouad published GHSA-7hwf-8pcj-33h4 Package Server (Nextcloud) Affected versions >= 32.0.0, >= 33.0.0, >= 34.0.0 Patched versions 32.0.13, 33.0.7, 34.0.2 Server (Nextcloud Enterprise) Affected versions >= 22.0.0.0, >= 23.0.0.0, >= 24.0.0.0, >= 25.0.0.0, >= 26.0.0.0, >= 27.0.0.0, >= 28.0.0.0, >= 29.0.0.0, >= 30.0.0.0, >= 31.0.0.0, >= 32.0.0, >= 33.0.0, >= 34.0.0 Patched versions 22.2.10.42, 23.0.12.38, 24.0.13.37, 25.0.13.32, 26.0.13.29, 27.1.11.29, 28.0.14.20, 29.0.16.19, 30.0.17.12, 31.0.14.8, 32.0.13, 33.0.7, 34.0.2 Description Impact By requesting previews of corrupted files a subsequent remote code execution (RCE) in Imagick (before 6.9.13-48 and 7.1.2-24) could be triggered, allowing an attacker to write arbitrary files. These files could then be used to further attack the system. However, the issue is limited to the following preview providers which are all not enabled by default: HEIC, Illustrator, PDF, Photoshop, Postscript, SGI, TGA, and TIFF. Additionally, the attacker must have access to either an account or a writable share link. Patches It is recommended that the Nextcloud Server is upgraded to 32.0.13, 33.0.7 or 34.0.2 It is recommended that the Nextcloud Enterprise Server is upgraded to 22.2.10.42, 23.0.12.38, 24.0.13.37, 25.0.13.32, 26.0.13.29, 27.1.11.29, 28.0.14.20, 29.0.16.19, 30.0.17.12, 31.0.14.8, 32.0.13, 33.0.7 or 34.0.2 Workarounds Each of them in itself is sufficient: Uninstall imagick from PHP Change config setting enable_previews to false in config/config.php Ensure config setting enabledPreviewProviders in config/config.php does not contain any of: OC\Preview\Font OC\Preview\HEIC OC\Preview\Illustrator OC\Preview\PDF OC\Preview\Photoshop OC\Preview\Postscript OC\Preview\SGI OC\Preview\TGA OC\Preview\TIFF References PullRequest Reported by Yordan Ganchev of watchTowr For more information If you have any questions or comments about this advisory: Create a post in nextcloud/security-advisories Customers: Open a support ticket at portal.nextcloud.com Severity High 7.4/ 10 CVSS v3 base metrics Attack vector Adjacent Attack complexity Low Privileges required Low User interaction Required Scope Unchanged Confidentiality High Integrity High Availability High CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H CVE ID No known CVE Weaknesses Weakness CWE-1395 ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 23/25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email:cert@support.renater.fr + =========================================================