Description
ownCloud is a file storage, synchronization, and sharing application. In ownCloud 10 prior to version 10.15.3, an attacker with administrative privileges can exploit a path traversal vulnerability in the system to execute arbitrary code. Upgrade ownCloud 10 to version 10.15.3 or later to receive a patch.
Published: 2026-07-06
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a relative path traversal flaw that allows an attacker with administrative privileges to supply crafted file paths that ownCloud 10 resolves incorrectly arbitrary files. a route to run any code on the server, compromising confidentiality, integrity, and availability of the entire file storage platform. The weakness is formally identified as CWE‑23.

Affected Systems

OwnCloud 10 installations running a version earlier than 10.15.3 are vulnerable. Once the application is upgraded to version 10.15.3 or later, the path‑traversal logic is corrected and the issue is eliminated. The vulnerability does not apply to releases newer than 10.15.3.

Risk and Exploitability

The issue carries a CVSS score of 8.0, indicating high severity. The EPSS score of less than 1 % suggests that exploitation is plausible but rare, and it is not listed in the CISA KEV catalog. Because the exploitation requires administrative privileges, the threat is primarily internal or compromised accounts, but the impact of successful exploitation is substantial, enabling full code execution on the server.

Generated by OpenCVE AI on July 26, 2026 at 20:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade ownCloud 10 to version 10.15.3 or later to apply the vendor patch.
  • Enforce strict access controls, limiting administrative privileges to trusted personnel and applying the principle of least privilege.
  • Monitor system logs for unauthorized file path traversal attempts and unexpected command execution patterns.

Generated by OpenCVE AI on July 26, 2026 at 20:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Owncloud
Owncloud owncloud
Vendors & Products Owncloud
Owncloud owncloud

Mon, 06 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description ownCloud is a file storage, synchronization, and sharing application. In ownCloud 10 prior to version 10.15.3, an attacker with administrative privileges can exploit a path traversal vulnerability in the system to execute arbitrary code. Upgrade ownCloud 10 to version 10.15.3 or later to receive a patch.
Title ownCloud 10 is vulnerable to Relative Path Traversal
Weaknesses CWE-23
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Owncloud Owncloud
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-08T03:56:35.191Z

Reserved: 2025-07-09T14:14:52.531Z

Link: CVE-2025-53829

cve-icon Vulnrichment

Updated: 2026-07-06T15:41:18.959Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T20:30:03Z

Weaknesses
  • CWE-23

    Relative Path Traversal