Junglewise Threat Intelligence

CVE-2025-53828: ownCloud SharePoint app SSRF in ownCloud Classic

CVE-2025-53828 · Severity: high · CVSS 8.5 · Published 2026-07-06

Vendors: ownCloud.

Executive brief

A security vulnerability exists in the SharePoint integration for ownCloud Classic, a platform used for corporate file storage and sharing. An attacker with administrative access can exploit this flaw to bypass security boundaries and execute unauthorized commands on the underlying server. This could lead to a complete system takeover, data theft, or disruption of file-sharing services.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the SharePoint application for ownCloud Classic prior to version 0.4.1. The flaw allows an attacker with administrative privileges to make unauthorized requests from the server, which can be further leveraged to achieve arbitrary code execution (RCE) on the host system. The vulnerability is tracked as CWE-918 and carries a high CVSS score due to the potential for a full scope change and impact on confidentiality, integrity, and availability. Users should upgrade ownCloud 10 to version 10.15.3 or later to receive the patched version of the SharePoint app.

Affected products

  • ownCloud SharePoint for ownCloud < 0.4.1
  • ownCloud ownCloud Classic < 10.15.3

Timeline

  • 2026-06-24: advisory: Initial GitHub advisory published
  • 2026-07-06: disclosed: NVD publication date

References

Related threats