CVE-2023-49105

CVE-2023-49105 is a critical-severity vulnerability in Owncloud Owncloud Server with a CVSS 3.x base score of 9.8. It is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, confirming it has been exploited in the wild (added 2026-08-27). The underlying weakness is classified as CWE-287.

Key facts

Description

An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0.

Frequently asked questions

What is CVE-2023-49105?
An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0.
How severe is CVE-2023-49105?
CVE-2023-49105 has a CVSS 3.x base score of 9.8, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
Is CVE-2023-49105 being actively exploited?
Yes. CVE-2023-49105 is on CISA's Known Exploited Vulnerabilities (KEV) catalog, added on 2026-08-27, which means active exploitation has been confirmed. It should be prioritised for remediation.
What products are affected by CVE-2023-49105?
CVE-2023-49105 affects Owncloud Owncloud Server. See the affected-products list for the exact vulnerable versions.
How do I fix CVE-2023-49105?
Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Because this CVE is known to be actively exploited, treat remediation as urgent — CISA KEV typically sets a short remediation deadline.
When was CVE-2023-49105 published?
CVE-2023-49105 was published on 2023-11-21 and last updated on 2026-08-28.

References

Affected products (1)

More vulnerabilities in Owncloud Owncloud Server

All CVEs affecting Owncloud Owncloud Server →

Other CWE-287 (Improper Authentication) vulnerabilities

Browse all CWE-287 (Improper Authentication) vulnerabilities →