Medium severity4.3NVD Advisory· Published Mar 28, 2017· Updated May 13, 2026
CVE-2016-9462
CVE-2016-9462
Description
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying restore privileges when restoring a file. The restore capability of Nextcloud/ownCloud was not verifying whether a user has only read-only access to a share. Thus a user with read-only access was able to restore old versions.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- github.com/nextcloud/server/commit/1208953ba1d4d55a18a639846bbcdd66a2d5bc5envdIssue TrackingPatchThird Party Advisory
- github.com/owncloud/core/commit/23383080731d092e079986464a8c4c9ffcb79f4cnvdIssue TrackingPatchThird Party Advisory
- github.com/owncloud/core/commit/3b056fa68ce502ceb0db9b446dab3b9e7b10dd13nvdIssue TrackingPatchThird Party Advisory
- github.com/owncloud/core/commit/c93eca49c32428ece03dd67042772d5fa62c8d6envdIssue TrackingPatchThird Party Advisory
- github.com/owncloud/core/commit/d31720b6f1e8c8dfeb5e8805ab35ad7c8000b2f1nvdIssue TrackingPatchThird Party Advisory
- nextcloud.com/security/advisory/nvdPatchVendor Advisory
- owncloud.org/security/advisory/nvdPatchVendor Advisory
- hackerone.com/reports/146067nvdExploitThird Party Advisory
- www.securityfocus.com/bid/97285nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.