


Perceptive Security
SOC/SIEM Consultancy

SharePoint for ownCloud is an application for using SharePoint with the file storage, synchronization, and sharing application ownCloud Classic. In SharePoint f…
Published:
5 juli 2026 om 22:00:00
Alert date:
6 juli 2026 om 17:02:30
Source:
nvd.nist.gov
Enterprise Applications, Web Technologies, Cloud & Virtualization
A Server-Side Request Forgery (SSRF) vulnerability exists in the SharePoint for ownCloud application prior to version 0.4.1, which corresponds to ownCloud 10 prior to version 10.15.3. An attacker with administrative privileges can exploit this SSRF flaw to execute arbitrary code on the affected system. The vulnerability affects the SharePoint integration app used with ownCloud Classic for file storage, synchronization, and sharing. The issue has been patched in SharePoint for ownCloud version 0.4.1, delivered as part of ownCloud 10 version 10.15.3. Users are strongly advised to upgrade to ownCloud 10.15.3 or later to remediate this vulnerability. The flaw requires administrative access to exploit, somewhat limiting the attack surface but still representing a significant risk in environments where admin accounts may be compromised.
Technical details
Mitigation steps:
Affected products:
SharePoint for ownCloud
ownCloud Classic
ownCloud 10
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2025-53828
https://github.com/owncloud/security-advisories/security/advisories/GHSA-4m66-rpfj-m5f6
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
