← All Advisories

CVE-2023-49105: ownCloud Improper

Status: KEV  |  Advisory ID: CVE-2023-49105

Key Details

CVECVE-2023-49105
CVSSCVSS 9.8 (Critical).
Affected productsownCloud ownCloud and ownCloud owncloud_server
Exploitation statusListed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation.
Classified asCWE-287 (Improper Authentication)
KEV listingAdded to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-08-27.
Exploitation prediction (EPSS)43% probability of exploitation in the next 30 days (99% percentile) -- FIRST.org's EPSS model.
Federal remediation deadline2026-08-30 (CISA KEV, Binding Operational Directive).

What to Know

An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2023-49105