A receiver of a federated share with access to the database with ownCloud version before 10.8 could update the permissions and therefore elevate their own permissions.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-35946.json"