/Vulnerability Library

ownCloud Guests - User Enumeration

CVE-2025-59716
Verified

Description

ownCloud Guests before 0.12.5 contains an unauthenticated user enumeration vulnerability caused by insufficient validation of the token in showPasswordForm at /apps/guests/register/{email}/{token}, letting unauthenticated attackers enumerate valid guest users, exploit requires no authentication.

Severity

Medium

CVSS Score

5.3

Exploit Probability

1%

Affected Product

guests

Published Date

March 25, 2026

Template Author

dhiyaneshdk

CVE-2025-59716.yaml
5.3Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVE ID:
cve-2025-59716
CWE ID:
cwe-203

References

https://nvd.nist.gov/vuln/detail/CVE-2025-59716https://gist.github.com/thesmartshadow/64ae0449e909174d0479a4f23657147fhttps://marketplace.owncloud.com/apps/guests

Remediation Steps

Update to version 0.12.5 or later.