---
id: CVE-2025-53827
title: >-
  ownCloud Core is the server-side component of the file storage,
  synchronization, and sharing application ownCloud Classic
summary: >-
  ownCloud Core is the server-side component of the file storage,
  synchronization, and sharing application ownCloud Classic. In versions prior
  to 10.15.3, the Updater on ownCloud 10 before 10.15.3 has an exposed dangerous
  method or functio…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-749
published: '2026-07-06'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T15:10:00.560'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-53827'
references:
  - url: >-
      https://github.com/owncloud/security-advisories/security/advisories/GHSA-hvcx-ph66-mmvw
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00615
epssPercentile: 0.47496
ingestedAt: '2026-09-30T16:10:06.712Z'
---

## Overview

ownCloud Core is the server-side component of the file storage, synchronization, and sharing application ownCloud Classic. In versions prior to 10.15.3, the Updater on ownCloud 10 before 10.15.3 has an exposed dangerous method or function. Attackers with administrative privileges may leverage functionality to execute arbitrary code. This issue has been fixed in version 10.15.3.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
