THREAT OPS › CVEs › CVE-2023-49105
CVE-2023-49105 — ownCloud Improper Authentication Vulnerability
ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured.
Vulnerability details
- Affected productsownCloud
- KEV remediation due2026-08-30
Related reporting
- August 2026 CVE Landscaperecordedfuture
- ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Bodythehackernews
- [NVD] CVE-2023-49105 (CRITICAL 9.8) — An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted evennvd
- CISA Adds Three Known Exploited Vulnerabilities to Catalogcisa_advisories
- [CISA KEV] CVE-2023-49105 — ownCloud ownCloud: ownCloud Improper Authentication Vulnerabilitycisa_kev