Junglewise Threat Intelligence

CVE-2025-53830: ownCloud Anti-Virus SSRF leading to code execution

CVE-2025-53830 · Severity: critical · CVSS 9.1 · Published 2026-07-06

Executive brief

The Anti-Virus application for ownCloud, which scans files for malware within the storage platform, contains a security flaw that could allow an administrative user to force the server to make unauthorized requests. If exploited, this could allow an attacker to execute malicious code on the server, potentially leading to a full system takeover or access to sensitive internal data. Organizations using ownCloud 10 should update their software or the specific anti-virus plugin to the latest versions to prevent this risk.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability (CWE-918) exists in the Anti-Virus for ownCloud application before version 1.2.3. The vulnerability allows an attacker with administrative privileges to manipulate the server into making unintended requests to internal or external resources. According to the advisory, this SSRF can be leveraged to achieve arbitrary code execution. The issue affects ownCloud 10 environments running versions prior to 10.15.3. A fix is available in Anti-Virus for ownCloud version 1.2.3 and ownCloud 10 version 10.15.3.

Affected products

  • ownCloud Anti-Virus for ownCloud 10 < 1.2.3
  • ownCloud ownCloud 10 < 10.15.3

Timeline

  • 2026-06-24: advisory: Initial advisory published by ownCloud
  • 2026-07-06: disclosed: CVE published in NVD dataset

References

Related threats