TECHNOLOGIES: NEXTCLOUD

Nextcloud Penetration Testing

A Nextcloud server is only as private as its sharing links, external storage credentials and admin settings. We test what your team actually configured, not the vendor’s defaults. CREST-certified testers, fixed price from £2,840 for a 2-day single-platform scope, quoted within 24 hours.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
10
Nextcloud Test Areas
FREE
Retest Until Closed
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
WHY IT MATTERS
Sharing

Every file a user can reach depends on how a link, a federated server or an external storage mount was configured, so we test which of those sharing paths are switched on for your instance.

Nextcloud risk sits in how sharing, storage and admin access were configured

A public link can be created with a password, an expiry date or as an upload-only File Drop folder where the recipient never has to sign in, and none of those settings is mandatory on its own. Federation extends that same access to other Nextcloud servers once an admin adds them to a trusted-server list, so a share can leave your instance without anyone noticing. We test which of these settings are switched on for a given share, and whether one meant to expire, require a password or block uploads still behaves that way after testing.

External Storage mounts connect Nextcloud to backends such as S3 buckets, SMB shares or FTP servers using credentials configured per mount, from a saved username and password to an RSA key or a session login, and every one of those credentials is a route into a system outside Nextcloud itself. Installed apps sit inside the same trust boundary, and an admin can restrict any app to specific groups rather than leaving it live for every user. We test who can reach each mount and which apps are actually enabled against who is meant to use them.

Admin accounts carry full control over users, apps and server configuration, so we check whether two-factor authentication is enforced for them and whether the trusted_domains list in config.php is scoped to the hostnames your organisation actually uses rather than left open to host header abuse. Server-side encryption, where enabled, runs through Nextcloud’s own encryption module and occ commands, and we test which module is active on your deployment and what its configuration actually covers, rather than assuming a specific setup.

SCOPE

What we pen test on a Nextcloud instance

NC-01

Public Link Password and Expiry Settings

Public share links can be created with a password, an automatic expiry date, or both, but neither setting is forced onto a share unless an admin enforces it globally. We test whether the links your organisation is actually sharing carry the protections your policy assumes.

NC-02

Upload-Only File Drop Folders

A File Drop share accepts uploads from anyone with the link without the uploader signing in or seeing existing files, which turns it into a one-way door into your storage if the link reaches the wrong audience. We test who can reach these folders and what they can do once inside.

NC-03

Federated Cloud Sharing

Federation lets an admin add other Nextcloud servers to a trusted-server list so shares can move between instances as user@https://remoteserver, extending your access boundary to infrastructure you do not control. We test which servers are trusted and whether that trust is scoped to servers your organisation actually works with.

NC-04

External Storage Credentials

External Storage mounts connect Nextcloud to backends such as S3, SMB or FTP using credentials configured per mount, from a saved username and password to an RSA key or a session login. We test how those credentials are stored, who can reach the mount, and whether a compromised Nextcloud account can pivot into the backend behind it.

NC-05

Installed App Exposure

Apps installed from the Nextcloud app store run inside your instance with whatever access Nextcloud grants them, and an admin can restrict any app to specific groups instead of leaving it enabled for every user. We test which apps are active, who can reach them, and whether a rarely used app has been left switched on organisation-wide.

NC-06

Admin Accounts and Two-Factor Authentication

Admin accounts carry full control over users, apps and server configuration, so we test whether two-factor authentication is enforced for every admin rather than optional, and whether an admin session can be reused or hijacked once issued.

NC-07

Server-Side Encryption Configuration

Server-side encryption is enabled and managed through Nextcloud’s own encryption module and occ commands, with a default module and the option to switch to a different one per deployment. We test which module is active on your instance and what its configuration actually protects, rather than assuming a specific setup.

NC-08

Trusted Domains and Host Header Checks

The trusted_domains array in config.php is the list of hostnames Nextcloud will accept logins for, and Nextcloud’s own documentation states that this check exists specifically to prevent host header poisoning. We test whether the configured list matches only the domains your organisation actually uses.

NC-09

Data Directory and Config File Placement

Nextcloud’s own hardening guidance recommends placing the data directory, and optionally config.php, outside the web root so a misconfigured web server cannot serve files or database credentials directly. We test whether that separation actually holds on your server, including whether the data directory is reachable over HTTP.

NC-10

Brute-Force and Login Throttling

Nextcloud throttles repeated failed logins at the application layer, and its own hardening guidance recommends pairing that with an OS-level tool such as fail2ban so brute-force traffic never reaches PHP or the database. We test whether that throttling is active and how it responds to a sustained credential-stuffing pattern.

OUR PROCESS

Nextcloud Penetration Testing: From Scope to Attestation

01

Scope and Access

We agree which sharing types, external storage mounts and installed apps are in scope, plus admin and standard user accounts for testing.

02

Sharing and Configuration Mapping

We map public link settings, federation trust, external storage credentials and the config.php values that control trusted domains and encryption against Nextcloud’s own hardening guidance.

03

Manual Testing

CREST-certified testers manually test public links, federated shares, external storage access and admin authentication, chaining findings where they compound.

04

Attestation and Retest

You get a technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest once fixes are deployed, and an attestation letter for auditors.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST Nextcloud pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

⚡24h reply ✓CREST tester ↻Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are written so your team can reference the report against each framework without translation work.

ISO 27001:2022

Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.

SOC 2 Type I & II

CC6 logical access, CC7 system operations, CC8 change management evidence.

PCI DSS

Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.

FCA SYSC

SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.

UK GDPR

Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.

Cyber Essentials Plus

Direct certification through our IASME body status, single-vendor delivery.

PRICING

Transparent Nextcloud Penetration Testing Pricing

Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
✓Free retests, no time limit
✓Free rescheduling
✓No cancellation fees
✓24-hour scope to active testing
✓Live findings to client portal
✓Executive + technical report
✓60-min walkthrough call
✓Letter of attestation
SMALL / SMB
£2,840–£4,390
2 to 4 testing days

Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£6,780–£9,520
5 to 7 testing days

Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From Nextcloud Penetration Testing

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

What access do you need to test our Nextcloud instance?

We need at least one standard user account and one admin account, plus details of any external storage mounts, federated servers or installed apps you want included. If public link sharing is in scope, a small set of test files and share links helps us cover realistic scenarios.

Will testing touch our live data?

We test whichever environment you give us access to. If that is production, we agree exclusions upfront, such as bulk deletes or mass sharing changes, and we do not run destructive tests against real files without that agreement in writing.

How long does a Nextcloud penetration test take?

A single Nextcloud instance sits in our 2-day single-platform scope, with a report typically landing around 5 working days after kickoff. An instance with heavy federation, multiple external storage backends or a large number of custom apps moves into a wider scope with more testing days.

Do you test self-hosted Nextcloud as well as hosted instances?

Yes. We test Nextcloud running on your own servers the same way as an instance hosted by a managed provider, adjusting the self-hosted configuration checks, such as trusted_domains and data directory placement, to whichever hosting model you use.

Are federated servers and external storage backends included by default?

They are included if they are switched on for your instance. Tell us during scoping which remote servers and storage backends should be treated as in scope, since a remote server you do not control is tested from your side of the trust relationship only.

What is out of scope for a single-platform Nextcloud test?

Infrastructure underneath Nextcloud, such as the host operating system, network or reverse proxy configuration, is out of scope for this test and covered by our cloud or Linux server testing instead. A separate application that only happens to integrate with Nextcloud is scoped and quoted separately.

Do you need our source code or server access?

No. Testing is black-box against the running instance by default. A grey-box option, where we review relevant config.php values, app permissions and external storage configuration alongside testing, is available for faster or deeper coverage of specific findings.

Does Nextcloud have a customer penetration-testing policy we need to follow?

Nextcloud’s own responsible disclosure policy states that testing is limited to your own install of Nextcloud Server, which matches how we scope this test: your instance, not Nextcloud’s shared infrastructure or other customers’ installs. We confirm Nextcloud’s current terms during scoping, and if your instance runs on infrastructure managed by a hosting provider, that provider’s own testing policy applies as well.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a fixed price for your Nextcloud instance

A Nextcloud server is only as private as its sharing links, external storage credentials and admin settings. We test what your team actually configured, not the vendor’s defaults. CREST-certified testers, fixed price from £2,840 for a 2-day single-platform scope, quoted within 24 hours.