Vulnerability record · CVE-2020-12850 · published 11 June 2020
CVE-2020-12850: Pydio cells improper privilege management vulnerability
Pydio · Cells
The following vulnerability applies only to the Pydio Cells Enterprise OVF version 2.0.4. Prior versions of the Pydio Cells Enterprise OVF (such as version 2.0.3) have a looser policy restriction allowing the “pydio” user to execute any privileged command using sudo. In version 2.0.4 of the appliance, the user pydio is responsible for running all the services and binaries that are contained in the Pydio Cells web application package, such as mysqld, cells, among others. This user has privileges restricted to run those services and nothing more.
Description
The following vulnerability applies only to the Pydio Cells Enterprise OVF version 2.0.4. Prior versions of the Pydio Cells Enterprise OVF (such as version 2.0.3) have a looser policy restriction allowing the “pydio” user to execute any privileged command using sudo. In version 2.0.4 of the appliance, the user pydio is responsible for running all the services and binaries that are contained in the Pydio Cells web application package, such as mysqld, cells, among others. This user has privileges restricted to run those services and nothing more.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/158002/Pydio-Cells-2.0.4-XSS-File-Write-Code-Execution.html | Third Party AdvisoryVDB Entry |
| https://www.coresecurity.com/advisories | Third Party Advisory |
| https://www.coresecurity.com/core-labs/advisories/pydio-cells-204-multiple-vulnerabilities | ExploitThird Party Advisory |
| http://packetstormsecurity.com/files/158002/Pydio-Cells-2.0.4-XSS-File-Write-Code-Execution.html | Third Party AdvisoryVDB Entry |
| https://www.coresecurity.com/advisories | Third Party Advisory |
| https://www.coresecurity.com/core-labs/advisories/pydio-cells-204-multiple-vulnerabilities | ExploitThird Party Advisory |
Track CVE-2020-12850 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-12850), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.