CVE-2019-12902: Pydio Cells

Medium severity, CVSS 6.5. EPSS: 1.1% chance of exploitation in the next 30 days.

Pydio Cells before 1.5.0 does incomplete cleanup of a user's data upon deletion. This allows a new user, holding the same User ID as a deleted user, to restore the deleted user's data.

Affected products

  • Pydio Cells: before 1.5.0 (fixed in 1.5.0)

Published 2019-06-20. Last modified 2026-06-17.