ownCloud Guests - User Enumeration
CVE-2025-59716
Verified
Description
ownCloud Guests before 0.12.5 contains an unauthenticated user enumeration vulnerability caused by insufficient validation of the token in showPasswordForm at /apps/guests/register/{email}/{token}, letting unauthenticated attackers enumerate valid guest users, exploit requires no authentication.
Severity
Medium
CVSS Score
5.3
Exploit Probability
1%
Affected Product
guests
Published Date
March 25, 2026
Template Author
dhiyaneshdk
CVE-2025-59716.yaml
5.3Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVE ID:
cve-2025-59716
CWE ID:
cwe-203
Remediation Steps
Update to version 0.12.5 or later.