CVE-2016-9461: Nextcloud Server
Medium severity, CVSS 4.3. EPSS: 2% chance of exploitation in the next 30 days.
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying edit check permissions on WebDAV copy actions. The WebDAV endpoint was not properly checking the permission on a WebDAV COPY action. This allowed an authenticated attacker with access to a read-only share to put new files in there. It was not possible to modify existing files.
Affected products
- Nextcloud Nextcloud Server: before 9.0.52 (fixed in 9.0.52)
- ownCloud ownCloud: before 9.0.4 (fixed in 9.0.4)
Published 2017-03-28. Last modified 2026-06-17.