Directory traversal vulnerability in the routing component in ownCloud Server before 7.0.6 and 8.0.x before 8.0.4, when running on Windows, allows remote attackers to reinstall the application or execute arbitrary code via unspecified vectors.
CVSS Vector
AV:N/AC:L/Au:N/C:C/I:C/A:CMicrosoft Windows
OSMicrosoftall versionsOwncloud
APPOwncloud≤ 7.0.5Owncloud Server
APPOwncloud8.0.08.0.28.0.3
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCEPath Traversal
CWE
Related vulnerabilities
CVE-2026-8398CRITICAL9.3⚠ KEVPL ✓same product
Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów
CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
CVE-2025-34028CRITICAL9.3⚠ KEVPL ✓same product
Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP
CVE-2024-7262CRITICAL9.3⚠ KEVPL ✓same product
Path Traversal w Kingsoft WPS Office — ładowanie dowolnej biblioteki Windows
CVE-2024-4577CRITICAL9.8⚠ KEVPL ✓same product
PHP CGI argument injection – RCE na Windows przez mechanizm Best-Fit