惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Jina AI
Jina AI
Recent Announcements
Recent Announcements
Attack and Defense Labs
Attack and Defense Labs
P
Proofpoint News Feed
WordPress大学
WordPress大学
雷峰网
雷峰网
Apple Machine Learning Research
Apple Machine Learning Research
博客园 - 叶小钗
I
Intezer
Hugging Face - Blog
Hugging Face - Blog
博客园 - 司徒正美
月光博客
月光博客
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
T
Threat Research - Cisco Blogs
有赞技术团队
有赞技术团队
T
Tailwind CSS Blog
S
Securelist
Cyberwarzone
Cyberwarzone
云风的 BLOG
云风的 BLOG
V
Visual Studio Blog
Stack Overflow Blog
Stack Overflow Blog
T
Tor Project blog
Project Zero
Project Zero
腾讯CDC
Recorded Future
Recorded Future
Help Net Security
Help Net Security
Spread Privacy
Spread Privacy
T
The Blog of Author Tim Ferriss
阮一峰的网络日志
阮一峰的网络日志
The Register - Security
The Register - Security
Google DeepMind News
Google DeepMind News
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
L
Lohrmann on Cybersecurity
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Security Latest
Security Latest
Cisco Talos Blog
Cisco Talos Blog
A
Arctic Wolf
N
News and Events Feed by Topic
D
DataBreaches.Net
V
Vulnerabilities – Threatpost
L
LangChain Blog
博客园 - 【当耐特】
V2EX - 技术
V2EX - 技术
Simon Willison's Weblog
Simon Willison's Weblog
Engineering at Meta
Engineering at Meta
The Last Watchdog
The Last Watchdog
Security Archives - TechRepublic
Security Archives - TechRepublic
D
Docker
C
CXSECURITY Database RSS Feed - CXSecurity.com
人人都是产品经理
人人都是产品经理

OpenCloud: Excellent file sharing: Secure and scalable cloud solutions

Webinar with ETES: OpenCloud for secure file management Support OpenCloud via GitHub Sponsors OpenCloud Production Release: Digital collaboration with structured content based on Markdown The OpenCloud Production Release enhances digital collaboration with structured, Markdown-based content OpenCloud at the IT Sovereignty and OSS Day II in Nuremberg OpenCloud at the GITEX 2026 OpenCloud and FUAGO: More flexibility for sovereign file collaboration OpenCloud and esatus show EUDI wallet login in OpenCloud New rolling release: Breadcrumb navigation and search shortcut OpenCloud at the Rack & Stack 2026 Rolling Release Feature Highlight: Favourites in OpenCloud OpenCloud and real-cis: Strengthening sovereign IT infrastructures OpenCloud at the Chemnitz Linux Days 2026 OpenCloud at the CS3 Conference 2026 in Oslo OpenCloud at the Digitaler Staat 2026 congress in Berlin OpenCloud and net42: Partnership for sovereign IT infrastructures Vulnerabilities in the code: Why transparency and enterprise licences provide security Rolling release feature highlight: Faster photo viewing in the Preview app OpenCloud and CAIRO: IT security and digital sovereignty We are at the FOSDEM 2026 in Brussels OpenCloud at the Univention Summit 2026 OpenCloud Production Release brings file management to provider level: true multi-tenancy and high availability OpenCloud Production Release: From Multi-tenancy to Helm Charts OpenCloud and Indeno: More performance through collaboration
OpenCloud developers find high severity vulnerability - patch available
Anne Gossing · 2026-02-05 · via OpenCloud: Excellent file sharing: Secure and scalable cloud solutions

05.02.2026 - Updates

Our security team at OpenCloud has discovered a vulnerability in Public Links and rated it CVSS 8.2 (High). This vulnerability was originally created in the code of ownCloud (Kiteworks) and was also included in the OCIS fork of OpenCloud.

Vulnerability discovered

As is customary in the open source environment, the team informed both CERN and ownCloud (Kiteworks) in advance, whose software is based in part on the same codebase as OpenCloud. This ensured that all affected parties were able to check their codebase and protect customer installations, such as the BayernCloud Schule (ByCS).

Today we are publicising this vulnerability and providing an important patch for OpenCloud.

We handled the discovery in accordance with responsible disclosure principles. Our customers with an Enterprise licence were protected at all times via their subscription. We ensure that every customer is informed and receives the necessary support for rapid protection and updates. Our support team is still available to answer any questions our customers may have.

Affected versions

CVE-2026-23989

All OpenCloud instances below version 4.0.3 and all instances below 5.0.2 are affected. The patched versions are 4.0.3 and 5.0.2.

Security patch available

With the release of the vulnerability today, we are also publishing the patch publicly online. We recommend that you schedule and install the update very immediately to ensure the security of your data.

You can find the current patch version in the advisory

Immediate action until the patch is applied

  • Disable the public links on your instances if you cannot apply the patch immediately.
  • Make the following configuration:
    • Configuration customisation
      • Docker Compose: Edit the docker-compose.yml and set GATEWAY_STORAGE_PUBLIC_LINK_ENDPOINT="" (empty string value) in the "environment" section of the "opencloud" container.
      • Kubernetes: Edit the deployment opencloud-api and set name: GATEWAY_STORAGE_PUBLIC_LINK_ENDPOINT
        value: "" (empty string)
        in the "env" section of the "spec" of the container "api".
  • Verify that the mitigation is active and perform the following test:
    • Create a public link as a test
    • Open the link in a private (no active login) browser tab.
    • You will see an error page with the message "File not found"
  • Inform your IT team and relevant stakeholders

Patch installation

  • The public patch version is available as of today, 05.02.2026 (can be found in the advisory)
  • Plan your maintenance window, ensure your backups, prepare your test/staging environment
  • Download the patch version 4.0.3
  • Test the patch in your test environment
  • Run the patch installation in the production environment
  • Verify the successful installation
  • Remove the temporary security configuration
  • if necessary. the temporary security configuration

For more information, please also take a look at our release notes and read our blog "Vulnerabilities in the code: Why transparency and enterprise licences provide security"

More news