CVE-2023-49105
CVE-2023-49105 is a critical-severity vulnerability in Owncloud Owncloud Server with a CVSS 3.x base score of 9.8. It is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, confirming it has been exploited in the wild (added 2026-08-27). The underlying weakness is classified as CWE-287.
Key facts
- Severity: Critical (CVSS 3.x base score 9.8)
- EPSS exploit prediction: 43% (99th percentile)
- Actively exploited: Yes — listed in CISA KEV (added 2026-08-27)
- Weakness: CWE-287
- Affected product: Owncloud Owncloud Server
- Published:
- Last modified:
Description
An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0.
Frequently asked questions
- What is CVE-2023-49105?
- An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0.
- How severe is CVE-2023-49105?
- CVE-2023-49105 has a CVSS 3.x base score of 9.8, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2023-49105 being actively exploited?
- Yes. CVE-2023-49105 is on CISA's Known Exploited Vulnerabilities (KEV) catalog, added on 2026-08-27, which means active exploitation has been confirmed. It should be prioritised for remediation.
- What products are affected by CVE-2023-49105?
- CVE-2023-49105 affects Owncloud Owncloud Server. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2023-49105?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Because this CVE is known to be actively exploited, treat remediation as urgent — CISA KEV typically sets a short remediation deadline.
- When was CVE-2023-49105 published?
- CVE-2023-49105 was published on 2023-11-21 and last updated on 2026-08-28.
References
- https://owncloud.com/security-advisories/webdav-api-authentication-bypass-using-pre-signed-urls/
- https://owncloud.org/security
- https://hunt.io/blog/chinese-speaking-operator-philippine-nuclear-naval-contractor
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-49105
Affected products (1)
- cpe:2.3:a:owncloud:owncloud_server:*:*:*:*:*:*:*:*
More vulnerabilities in Owncloud Owncloud Server
- CVE-2015-4716 — Critical (CVSS 10.0): Directory traversal vulnerability in the routing component in ownCloud Server before 7.0.6 and 8.0.x before 8.0.4, when…
- CVE-2014-2052 — Critical (CVSS 9.8): Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read…
- CVE-2015-7699 — Critical (CVSS 9.0): The files_external app in ownCloud Server before 7.0.9, 8.0.x before 8.0.7, and 8.1.x before 8.1.2 allows remote…
- CVE-2015-4718 — Critical (CVSS 9.0): The external SMB storage driver in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 allows…
- CVE-2016-1499 — High (CVSS 8.5): ownCloud Server before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2 allow remote authenticated users to obtain…
- CVE-2015-4717 — High (CVSS 7.8): The filename sanitization component in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 does…
All CVEs affecting Owncloud Owncloud Server →
Other CWE-287 (Improper Authentication) vulnerabilities
- CVE-2026-83099 — Critical (CVSS 10.0): Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode).…
- CVE-2026-83059 — Critical (CVSS 10.0): Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server).…
- CVE-2026-83021 — Critical (CVSS 10.0): Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported…
- CVE-2026-83020 — Critical (CVSS 10.0): Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized…
- CVE-2026-71133 — Critical (CVSS 10.0): Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).…
- CVE-2026-76658 — Critical (CVSS 10.0): A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an…
Browse all CWE-287 (Improper Authentication) vulnerabilities →