


Perceptive Security
SOC/SIEM Consultancy

ownCloud is a file storage, synchronization, and sharing application. In ownCloud 10 prior to version 10.15.3, an attacker with administrative privileges can ex…
Published:
5 juli 2026 om 22:00:00
Alert date:
6 juli 2026 om 17:02:30
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications, Zero-Day Vulnerabilities
A path traversal vulnerability exists in ownCloud 10 prior to version 10.15.3 that allows an attacker with administrative privileges to execute arbitrary code on the system. The vulnerability affects ownCloud, a file storage, synchronization, and sharing application. Exploitation requires administrative access, which somewhat limits the attack surface but still poses significant risk in environments with multiple administrators or compromised admin accounts. The issue has been patched in ownCloud 10 version 10.15.3. Users are advised to upgrade immediately to mitigate the risk. The vulnerability is tracked as CVE-2025-53829 and has been published on NVD as well as GitHub Security Advisories.
Technical details
Mitigation steps:
Affected products:
ownCloud 10 (prior to 10.15.3)
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2025-53829
https://github.com/owncloud/security-advisories/security/advisories/GHSA-4439-4wxm-c9px
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
