---
id: CVE-2025-53829
title: 'ownCloud is a file storage, synchronization, and sharing application'
summary: >-
  ownCloud is a file storage, synchronization, and sharing application. In
  ownCloud 10 prior to version 10.15.3, an attacker with administrative
  privileges can exploit a path traversal vulnerability in the system to execute
  arbitrary code.…
severity: high
cvss: 8
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-23
published: '2026-07-06'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T15:10:00.560'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-53829'
references:
  - url: >-
      https://github.com/owncloud/security-advisories/security/advisories/GHSA-4439-4wxm-c9px
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00511
epssPercentile: 0.41323
ingestedAt: '2026-09-30T16:10:06.758Z'
---

## Overview

ownCloud is a file storage, synchronization, and sharing application. In ownCloud 10 prior to version 10.15.3, an attacker with administrative privileges can exploit a path traversal vulnerability in the system to execute arbitrary code. Upgrade ownCloud 10 to version 10.15.3 or later to receive a patch.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
