CVE-2020-36252: ownCloud Server

Medium severity, CVSS 5.7. EPSS: 0.5% chance of exploitation in the next 30 days.

ownCloud Server 10.x before 10.3.1 allows an attacker, who has one outgoing share from a victim, to access any version of any file by sending a request for a predictable ID number.

Affected products

  • ownCloud ownCloud Server: from 10.0.9, before 10.3.1 (fixed in 10.3.1)

Published 2021-02-19. Last modified 2026-06-17.