CVE-2023-49105

Published Nov 21, 2023

Last updated 9 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2023-49105 is an authentication bypass vulnerability found in ownCloud Server, specifically within its WebDAV API implementation. This flaw arises from the improper validation of pre-signed URLs when the targeted user does not have a signing-key configured. An attacker can exploit this vulnerability by knowing a victim's username, allowing them to access, modify, or delete any of that user's files without needing to authenticate. This issue affects ownCloud Server versions 10.6.0 through 10.13.0.

Description
An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0.
Source
cve@mitre.org
NVD status
Analyzed
Products
owncloud_server

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
ownCloud Improper Authentication Vulnerability
Exploit added on
Aug 27, 2026
Exploit action due
Aug 30, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

nvd@nist.gov
CWE-287
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-287

Social media

Hype score
Not currently trending
  1. Çin Bağlantılı Hackerlar, Filipinler'in Nükleer Araştırma Kurumunu ownCloud Açığıyla Hedef Aldı! Çin kökenli bir tehdit aktörü, dosya paylaşım platformu ownCloud'daki CVE-2023-49105 (CVSS 9.8) kimlik doğrulama atlatma açığını kullanarak Filipinler'in nük

    @BTHaberler

    1 Sept 2026

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🇵🇭ownCloudの脆弱性が悪用され、フィリピンの原子力研究機関から核関連レコードが盗まれる(CVE-2023-49105) ⚠️WordPressプラグイン/テーマに5件の重大な脆弱性、サイト乗っ取りやRCEが可能に(CVE-2026-82222

    @MachinaRecord

    31 Aug 2026

    206 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CISA adds three more actively exploited vulnerabilities; ownCloud and Artifactory deserve particular attention On August 27, CISA added three vulnerabilities to its Known Exploited Vulnerabilities catalog based on evidence of real-world exploitation: CVE-2023-49105 — ownCloud

    @DailyDarkWeb

    28 Aug 2026

    3653 Impressions

    1 Retweet

    4 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. CISA KEV Catalog updates include CVE-2023-49105, CVE-2026-53362, and CVE-2026-66384. These actively exploited flaws can fully compromise device security. #CISAKEV #Cybersecurity #CVE202349105 #CVE202653362 #CVE202666384 https://t.co/Ne9C3Sf3er

    @Daily_CyberSec

    28 Aug 2026

    402 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに以下3脆弱性を追加。 - CVE-2023-49105 (ownCloud) - CVE-2026-53362 (Linux Kernel) - CVE-2026-66384 (JFrog) 対処期限は上2件が3日後の8/30、J

    @__kokumoto

    27 Aug 2026

    700 Impressions

    0 Retweets

    4 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🛡️ We added ownCloud vulnerability CVE-2023-49105, Linux kernel vulnerability CVE-2026-53362 & JFrog Artifactory vulnerability CVE-2026-66384 to our KEV Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cybersecurity h

    @CISACyber

    27 Aug 2026

    7323 Impressions

    10 Retweets

    36 Likes

    3 Bookmarks

    5 Replies

    0 Quotes

  7. Serious breach: Chinese-speaking hackers exploited CVE-2023-49105 in ownCloud and CVE-2024-28000 in WordPress to steal reactor files, employee data, and full archives from a Philippine nuclear agency and naval contractor. Patch ownCloud 10.13.3+, update LiteSpeed Cache to 6.4+, h

    @dailytechonx

    27 Aug 2026

    59 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations