CISA added CVE-2023-49105, a critical (CVSS 9.8) authentication bypass in ownCloud core, to the Known Exploited Vulnerabilities catalog on 2026-08-27 with a three-day remediation deadline of 2026-08-30.
What Is It
CVE-2023-49105 is an improper authentication flaw (CWE-287) in ownCloud owncloud/core. Pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. As a result, an attacker who knows a victim's username can access, modify, or delete any of that victim's files without authentication, provided the victim has no signing-key configured.
The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network-reachable, low complexity, no privileges, no user interaction, with high impact to confidentiality, integrity, and availability.
Why It Matters
CISA's KEV entry confirms active exploitation. The accompanying SSVC assessment scores this as exploitation: active, automatable: yes, technical impact: total. On CISA's scoring definitions, that combination indicates the flaw is amenable to automated exploitation and that a successful attack would give an operator full control over the affected file data; the scores are a decision-support rating rather than a report of observed attack tooling. Because exploitation requires only a known username and no credentials, internet-exposed ownCloud instances are directly at risk. Known ransomware campaign use is listed as Unknown.
What's Vulnerable
- ownCloud Server (
cpe:2.3:a:owncloud:owncloud_server) - Affected versions: 10.6.0 (earliest affected) through versions prior to 10.13.1
- Exploitable condition: the targeted user account has no signing-key configured
Patch Status
Fixed in ownCloud core 10.13.1. CISA's required action is to apply mitigations in accordance with vendor instructions, in compliance with BOD 26-04 "Prioritizing Security Updates Based on Risk" and CISA's "Forensics Triage Requirements." Organizations should follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and adhering to BOD 26-04 patching guidelines. Due date: 2026-08-30.
Sources
- ownCloud Security Advisory; WebDAV API Authentication Bypass Using Pre-Signed URLs: https://owncloud.com/security-advisories/webdav-api-authentication-bypass-using-pre-signed-urls/
- ownCloud Security: https://owncloud.org/security
- NVD, CVE-2023-49105: https://nvd.nist.gov/vuln/detail/CVE-2023-49105
- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-49105
- CISA BOD 26-04; Prioritizing Security Updates Based on Risk: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- CISA BOD 26-04 Implementation Guidance / Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk