SYS::ONLINE
Wasteland.
Briefs2298
Issues25
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2023-49105 2026-08-27

CVE-2023-49105: ownCloud WebDAV Authentication Bypass Added to CISA KEV

"CISA added CVE-2023-49105, a critical (CVSS 9.8) authentication bypass in ownCloud core, to the Known Exploited Vulnerabilities catalog on 2026-08-27 with a three-day remediation deadline of 2026-08-30."

CISA added CVE-2023-49105, a critical (CVSS 9.8) authentication bypass in ownCloud core, to the Known Exploited Vulnerabilities catalog on 2026-08-27 with a three-day remediation deadline of 2026-08-30.

What Is It

CVE-2023-49105 is an improper authentication flaw (CWE-287) in ownCloud owncloud/core. Pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. As a result, an attacker who knows a victim's username can access, modify, or delete any of that victim's files without authentication, provided the victim has no signing-key configured.

The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network-reachable, low complexity, no privileges, no user interaction, with high impact to confidentiality, integrity, and availability.

Why It Matters

CISA's KEV entry confirms active exploitation. The accompanying SSVC assessment scores this as exploitation: active, automatable: yes, technical impact: total. On CISA's scoring definitions, that combination indicates the flaw is amenable to automated exploitation and that a successful attack would give an operator full control over the affected file data; the scores are a decision-support rating rather than a report of observed attack tooling. Because exploitation requires only a known username and no credentials, internet-exposed ownCloud instances are directly at risk. Known ransomware campaign use is listed as Unknown.

What's Vulnerable

Patch Status

Fixed in ownCloud core 10.13.1. CISA's required action is to apply mitigations in accordance with vendor instructions, in compliance with BOD 26-04 "Prioritizing Security Updates Based on Risk" and CISA's "Forensics Triage Requirements." Organizations should follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and adhering to BOD 26-04 patching guidelines. Due date: 2026-08-30.

Sources