Status: KEV | Advisory ID: CVE-2023-49105
| CVE | CVE-2023-49105 |
| CVSS | CVSS 9.8 (Critical). |
| Affected products | ownCloud ownCloud and ownCloud owncloud_server |
| Exploitation status | Listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation. |
| Classified as | CWE-287 (Improper Authentication) |
| KEV listing | Added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-08-27. |
| Exploitation prediction (EPSS) | 43% probability of exploitation in the next 30 days (99% percentile) -- FIRST.org's EPSS model. |
| Federal remediation deadline | 2026-08-30 (CISA KEV, Binding Operational Directive). |
An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0.
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2023-49105 |