CVE Tools

CVE-2023-49105

Exploited in the wild. In CISA KEV since 2026‑08‑27. A vendor fix is available.

Published Updated Sources: CVE.org, NVD, BDU

What to do

The vendor has published a fix. Version details are below where the sources state them.

Steps

Written by AI from the record
  1. Check whether you use ownCloud server and what version is running.
  2. Check whether your ownCloud is reachable from the internet (directly or via a public URL/load balancer).
  3. Check whether any ownCloud user accounts are missing a signing key configuration (per your ownCloud admin settings).
  4. Upgrade ownCloud server to fixed version 10.13.1 immediately (this is the vendor fix target for CVE-2023-49105).

What it is

From the CVE record

An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0.

In plain language

Written by AI from the record

CVE-2023-49105 lets an attacker, without logging in, access and change or delete files in an ownCloud server for a known username; if your ownCloud is reachable from the internet, you should treat this as an urgent fix and update to 10.13.1.

CVE-2023-49105 is an unauthenticated file access/modify/delete flaw in ownCloud’s pre-signed URL handling when the target user has no signing key configured, allowing attackers who know a victim username to act on that user’s files via network access.

If you're affected

  • Stolen customer or business files
  • Ransomware-style data destruction
  • Account-level data tampering
  • Loss of trust and legal exposure

Exploitation

Where each signal puts this CVE on the scale from published to confirmed exploited.

EPSS99th
CISA KEV
CISA KEV

Listed as exploited in the wild since 2026-08-27.

US federal agencies must remediate by 2026-08-30.

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Public exploits

No public exploit or proof of concept found in the sources we track.

EPSS

43% chance of exploitation activity in the next 30 days, which ranks it in the 99th percentile of scored CVEs.

Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.

Lifecycle

16 events over 1029 days, from the signal feeds we watch.

  1. Analysis publishedCISA's Newest KEV Entries Are the Exact Bugs an OpenAI Model Used to Breach Hugging Face
  2. Patch availablepatch available, record updated, record updated
  3. Added to CISA KEVpatch available, record updated
  4. OpenVAS check added
  5. EPSS band changehigh → moderate
  6. Nuclei check added

Affected products

And 1 more affected product. See all after sign-in

Technical detail

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Scored 9.8 by NVD.

How it is reached

  • Attack Vector NetworkExploitable remotely over the network without any special conditions
  • Attack Complexity LowNo special conditions — the attack can be reliably reproduced
  • Privileges Required NoneNo authentication required — anyone can exploit this
  • User Interaction NoneNo user interaction needed — fully automated exploitation

Scope

  • Scope UnchangedImpact is limited to the vulnerable component itself

Impact if exploited

  • Confidentiality HighTotal information disclosure — all data in the component is compromised
  • Integrity HighTotal loss of integrity — attacker can modify any data in the component
  • Availability HighTotal denial of service — the component is completely unavailable

Weaknesses

ATT&CK techniques

Mapped from the weaknesses above (CWE to ATT&CK), not observed in attacks.

Sources

Watch the software you run.

My Stack ranks new CVEs for your products by real-world exploitation, so the next exploited one reaches you without reading every advisory.

We'll flag the next CVE, public exploit or patch for Owncloud Server, not every advisory. This one: actively exploited.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store