SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2025-53827

CRITICAL · CVSS 9.1 EPSS 0.36% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-06 · Last synced 2026-08-05

CyberRota Analysis

AI-Generated

The ownCloud Core Updater in versions prior to 10.15.3 contains an exposed method that allows attackers with administrative privileges to execute arbitrary code, posing a critical security risk. Organizations using affected versions of ownCloud should prioritize upgrading to version 10.15.3 to mitigate this vulnerability and protect their file storage and synchronization services from potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2025-53827
Severity
CRITICAL
CVSS
9.1
EPSS
0.36%

Original NVD Description

ownCloud Core is the server-side component of the file storage, synchronization, and sharing application ownCloud Classic. In versions prior to 10.15.3, the Updater on ownCloud 10 before 10.15.3 has an exposed dangerous method or function. Attackers with administrative privileges may leverage functionality to execute arbitrary code. This issue has been fixed in version 10.15.3.