CVE-2020-10254: ownCloud

Medium severity, CVSS 5.9. EPSS: 1.9% chance of exploitation in the next 30 days.

An issue was discovered in ownCloud before 10.4. An attacker can bypass authentication on a password-protected image by displaying its preview.

Affected products

  • ownCloud ownCloud: before 10.4.0 (fixed in 10.4.0)

Published 2021-02-19. Last modified 2026-06-17.