CVE-2020-36248: ownCloud Client

Medium severity, CVSS 4.6. EPSS: 0.1% chance of exploitation in the next 30 days.

The ownCloud application before 2.15 for Android allows attackers to use adb to include a PIN preferences value in a backup archive, and consequently bypass the PIN lock feature by restoring from this archive.

Affected products

  • ownCloud ownCloud Client: before 2.15 (fixed in 2.15)

Published 2021-02-19. Last modified 2026-06-17.