CVE-2016-1500: ownCloud

Low severity, CVSS 3.1. EPSS: 0.9% chance of exploitation in the next 30 days.

ownCloud Server before 7.0.12, 8.0.x before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2, when the "file_versions" application is enabled, does not properly check the return value of getOwner, which allows remote authenticated users to read the files with names starting with ".v" and belonging to a sharing user by leveraging an incoming share.

Affected products

  • ownCloud ownCloud: up to and including 7.0.11; version 8.2.0 only; version 8.2.1 only
  • ownCloud ownCloud Server: version 8.0.0 only; version 8.0.2 only; version 8.0.3 only; version 8.0.4 only; version 8.0.5 only; version 8.0.6 only; …

Published 2016-01-08. Last modified 2026-06-17.