Junglewise Threat Intelligence

CVE-2025-53827: ownCloud Core remote code execution in Updater component

CVE-2025-53827 · Severity: critical · CVSS 9.1 · Published 2026-07-06

Vendors: ownCloud.

Executive brief

ownCloud Core, the server-side component of the ownCloud Classic file sharing platform, contains a vulnerability in its update mechanism. An attacker with administrative privileges can exploit an exposed function to run unauthorized commands on the server. This could lead to a complete takeover of the file storage system, potentially resulting in the theft or deletion of all hosted customer data.

Technical details

A vulnerability classified as CWE-749 (Exposed Dangerous Method or Function) exists in the ownCloud 10 Updater component. The flaw allows an attacker with high-level administrative privileges to invoke an unrestricted method or function within the server-side code. By leveraging this exposed interface, the attacker can achieve remote code execution (RCE) on the underlying host. The vulnerability is reachable over the network without user interaction, though it requires valid administrative credentials. The issue is resolved in version 10.15.3; users unable to upgrade should disable the Updater component as a workaround.

Affected products

  • ownCloud ownCloud Core < 10.15.3

Timeline

  • 2026-06-24: advisory: Initial advisory published by ownCloud security team
  • 2026-07-06: disclosed: CVE-2025-53827 published to NVD
  • 2026-07-06: patched: Fix released in version 10.15.3

References