Description
Anti-Virus for ownCloud is an anti-virus application for file storage, synchronization, and sharing application ownCloud. Versions of Anti-Virus for ownCloud before 1.2.3 are vulnerable to Server-Side Request Forgery (SSRF). This corresponds to versions of ownCloud 10 prior to 10.15.3. Upgrade ownCloud 10 to version 10.15.3 or later or upgrade Anti-Virus for ownCloud 10 to version 1.2.3 or later to receive a fix.
Published: 2026-07-06
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Anti‑Virus for ownCloud is a plugin that scans files for malware in the ownCloud 10 file‑storage platform. Versions of the plugin before 1.2.3 contain a Server‑Side Request Forgery flaw that allows an adversary to cause the server to issue arbitrary HTTP or HTTPS requests to internal or external hosts. The vulnerability is classified under CWE-918 and can potentially be used to access resources the server has connectivity to; the base score of 9.1 indicates a severe risk, but the EPSS noted as less than 1%, suggesting a very low probability of exploitation at this time. The flaw is not listed in the CISA KEV catalog, meaning no publicly disclosed exploits exist yet. The likely attack vector is inferred to involve triggering a file‑scan operation—such as uploading a file or invoking an API endpoint that constructs the malicious request. Because the description does not detail specific data disclosures, the actual impact is limited to the ability to contact arbitrary hosts from the server’s network.

Affected Systems

All deployments running ownCloud 10 with the anti‑virus plugin version earlier than 1.2.3 are affected, version .3. Versions equal to or newer than 1.2.3 for the plugin or 10.15.3 for ownCloud are not impacted.

Risk and Exploitability

The CVSS score of 9.1 indicates a severe risk. The EPSS score of less than 1% reflects a very low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, so no public exploits are known. Based on the description, the likely attack vector involves an authenticated or unauthenticated user triggering a file‑scan operation—such as uploading a file or calling a scan API—which causes the server to construct and send a malicious HTTP or HTTPS request to an arbitrary host. The attacker can gain the server’s outbound network reach, potentially accessing internal resources or pivoting to other systems. The attack requires the anti‑virus plugin to be enabled and the server to have outbound connectivity to the target host.

Generated by OpenCVE AI on July 26, 2026 at 20:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Anti‑Virus for ownCloud to version 1.2.3 or newer.
  • Upgrade ownCloud 10 to version 10.15.3 or newer.
  • Restrict outbound network calls to trusted hosts to constrain potential gains from an SSRF attack.

Generated by OpenCVE AI on July 26, 2026 at 20:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Owncloud
Owncloud anti-virus For Owncloud
Owncloud owncloud
Vendors & Products Owncloud
Owncloud anti-virus For Owncloud
Owncloud owncloud

Mon, 06 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description Anti-Virus for ownCloud is an anti-virus application for file storage, synchronization, and sharing application ownCloud. Versions of Anti-Virus for ownCloud before 1.2.3 are vulnerable to Server-Side Request Forgery (SSRF). This corresponds to versions of ownCloud 10 prior to 10.15.3. Upgrade ownCloud 10 to version 10.15.3 or later or upgrade Anti-Virus for ownCloud 10 to version 1.2.3 or later to receive a fix.
Title Anti-Virus for ownCloud 10 is vulnerable to Server-Side Request Forgery (SSRF)
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Owncloud Anti-virus For Owncloud Owncloud
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-08T03:56:35.944Z

Reserved: 2025-07-09T14:14:52.531Z

Link: CVE-2025-53830

cve-icon Vulnrichment

Updated: 2026-07-06T16:16:49.522Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T20:30:03Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)