← Vulnerability feed

Vulnerability record · CVE-2014-2048 · published 26 March 2018

CVE-2014-2048: Owncloud improper access control vulnerability

Owncloud · Owncloud

The user_openid app in ownCloud Server before 5.0.15 allows remote attackers to obtain access by leveraging an insecure OpenID implementation.

9.8 CVSS 3.0 Critical EPSS 2.6% · top 15.3% CWE-284 · Improper access control
9.8CVSS 3.0 base score, v2 7.5
2.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

The user_openid app in ownCloud Server before 5.0.15 allows remote attackers to obtain access by leveraging an insecure OpenID implementation.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-2048 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2015-4716Owncloud path traversal vulnerabilityDirectory traversal vulnerability in the routing component in ownCloud Server before 7.0.6 and 8.0.x before 8.0.4, when running on Windows, allows re…EPSS 25%9.8CVE-2021-35946Owncloud improper privilege management vulnerabilityA receiver of a federated share with access to the database with ownCloud version before 10.8 could update the permissions and therefore elevate thei…EPSS 1.5%9.8CVE-2014-2052Owncloud xml external entity (xxe) vulnerabilityZend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of s…EPSS 2.5%9.1CVE-2020-28645Owncloud improper input validation vulnerabilityDeleting users with certain names caused system files to be deleted. Risk is higher for systems which allow users to register themselves and have the…EPSS 1.2%9.0CVE-2015-7698Owncloud smb os command injection vulnerabilityicewind1991 SMB before 1.0.3 allows remote authenticated users to execute arbitrary SMB commands via shell metacharacters in the user argument in the…EPSS 2.5%9.0CVE-2015-4718Owncloud os command injection vulnerabilityThe external SMB storage driver in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 allows remote authenticated users to exec…EPSS 3.0%8.5CVE-2016-1499Owncloud information exposure vulnerabilityownCloud Server before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2 allow remote authenticated users to obtain sensitive information from a dir…EPSS 3.5%8.3CVE-2020-10252Owncloud server-side request forgery (ssrf) vulnerabilityAn issue was discovered in ownCloud before 10.4. Because of an SSRF issue (via the apps/files_sharing/external remote parameter), an authenticated at…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2014-2048), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.