ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body
Reported exploitedownCloudChinese-speaking threat actorOur summary
CISA has added ownCloud vulnerability CVE-2023-49105 to its Known Exploited Vulnerabilities catalog after a Chinese-speaking threat actor used it to compromise a nuclear research facility in the Philippines. The critical flaw, affecting versions 10.6.0 through 10.13.0, allows unauthenticated file access via WebDAV pre-signed URLs when no signing key is configured, leading to the theft of approximately 372 MB of sensitive documents including strategic plans and reactor data. Federal agencies are advised to upgrade to version 10.13.1 by August 30, 2026.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.