Description
SharePoint for ownCloud is an application for using SharePoint with the file storage, synchronization, and sharing application ownCloud Classic. In SharePoint for ownCloud prior to version 0.4.1, which corresponds to ownCloud 10 prior to 10.15.3, an attacker with administrative privileges can use a SSRF vulnerability in the SharePoint app to execute arbitrary code on the system. Upgrade ownCloud 10 to version 10.15.3 or later to receive SharePoint for ownCloud 0.4.1, the fixed version.
Published: 2026-07-06
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a server‑side request forgery in the SharePoint for ownCloud app integrated with ownCloud Classic. Attackers who have administrative privileges can send crafted requests from the ownCloud server to arbitrary URLs. Because the request originates from the host, the attacker can retrieve internal resources, access the local network, and ultimately trigger code execution on the host machine. The flaw is classified as CWE‑918 and has a CVSS base score of 8.5, indicating high severity. The EPSS score is < 1 %, indicating a very low exploitation probability. The vulnerability is not listed in CISA KEV. Exploitation requires administrative access to ownCloud; once obtained, the SSRF allows the attacker to execute arbitrary code. The absence of public exploitation data suggests limited known attacks, but the and low EPSS for systems with exposed administrative interfaces.

Affected Systems

The flaw affects ownCloud SharePoint and ownCloud 10—specifically any installation of SharePoint for ownCloud prior to version 0.4.1 and ownCloud 10 prior to 10.15.3.

Risk and Exploitability

The CVSS base score of 8.5 indicates high severity, while an EPSS score of < 1 % suggests a very low likelihood of exploitation in the wild. The vulnerability is not listed in CISA KEV, so no public exploit signatures have been seen yet. Exploitation requires administrative privilege within ownCloud; after that, the SSRF can be used to send requests to internal or external addresses, potentially allowing arbitrary code execution. The attack is local to the ownCloud server, meaning the exploitable endpoint must be reachable from the server itself. Network controls that restrict outbound traffic or use a web proxy can mitigate the risk, but the most effective defense is to upgrade the application to the fixed version.

Generated by OpenCVE AI on July 26, 2026 at 20:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade ownCloud to version 10.15.3 or later, which includes SharePoint for ownCloud 0.4.1.
  • Restrict outbound traffic from the ownCloud server to limit potential SSRF exploitation.
  • Conduct internal vulnerability scans to confirm that there are no remaining SSRF endpoints exposed.

Generated by OpenCVE AI on July 26, 2026 at 20:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 07 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Owncloud
Owncloud owncloud
Owncloud sharepoint
Vendors & Products Owncloud
Owncloud owncloud
Owncloud sharepoint

Mon, 06 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description SharePoint for ownCloud is an application for using SharePoint with the file storage, synchronization, and sharing application ownCloud Classic. In SharePoint for ownCloud prior to version 0.4.1, which corresponds to ownCloud 10 prior to 10.15.3, an attacker with administrative privileges can use a SSRF vulnerability in the SharePoint app to execute arbitrary code on the system. Upgrade ownCloud 10 to version 10.15.3 or later to receive SharePoint for ownCloud 0.4.1, the fixed version.
Title SharePoint for ownCloud 10 is vulnerable to Server-Side Request Forgery (SSRF)
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Owncloud Owncloud Sharepoint
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-08T03:56:34.441Z

Reserved: 2025-07-09T14:14:52.530Z

Link: CVE-2025-53828

cve-icon Vulnrichment

Updated: 2026-07-07T14:04:48.899Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T20:30:03Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)