A receiver of a federated share with access to the database with ownCloud version before 10.8 could update the permissions and therefore elevate their own permissions.
https://owncloud.com/security-advisories/cve-2021-35946/
https://doc.owncloud.com/server/admin_manual/release_notes.html