CVE-2025-59716Disclosure(owncloud / guests)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

ownCloud Guests before 0.12.5 allows unauthenticated user enumeration via the /apps/guests/register/{email}/{token} endpoint. Because of insufficient validation of the supplied token in showPasswordForm, the server responds differently when an e-mail address corresponds to a valid pending guest user rather than a non-existent user.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-203

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • guests

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
guests

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-26: 1Technical Details · 2026-03-26: 103-26
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2025-59716 - medium 🚨 ownCloud Guests - User Enumeration > ownCloud Guests before 0.12.5 contains an unauthenticated user enumeration vulnerabil... 👾 https://cloud.projectdiscovery.io/library/CVE-2025-59716 @pdnuclei #NucleiTemplates #cve

    Post summary

    The post announces CVE‑2025‑59716 as a medium‑severity unauthenticated user enumeration flaw in ownCloud Guests before v0.12.5, but offers no PoC, exploit, patch, or evidence of active exploitation.

    00010243
    905 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appowncloudguests---

Explore more