• CISA KEV
  • EXPLOITED
  • PoC PUBLIC

CVE-2023-49105: pre-auth improper authentication in ownCloud ownCloud

Unauthenticated attackers can read, alter, or remove files stored on ownCloud by exploiting a flaw that accepts pre-signed URLs even when an account has no signing-key configured; this issue is tracked as CVE-2023-49105. Reports show the problem exists in ownCloud releases beginning with 10.6.0 and affecting versions before 10.13.1. Exploitation requires only network access and knowledge of a valid username for the targeted account — no login or user interaction is necessary when the signing-key is absent.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.42919
CWE
CWE-287
KEV DUE DATE
PATCH
Not yet

DIRAS TAKE

Urgent — CISA placed this vulnerability on the Known Exploited Vulnerabilities catalog with a tight remediation deadline, indicating rapid action is required for exposed systems.

What is CVE-2023-49105?

Unauthenticated attackers can read, alter, or remove files stored on ownCloud by exploiting a flaw that accepts pre-signed URLs even when an account has no signing-key configured; this issue is tracked as CVE-2023-49105. Reports show the problem exists in ownCloud releases beginning with 10.6.0 and affecting versions before 10.13.1. Exploitation requires only network access and knowledge of a valid username for the targeted account — no login or user interaction is necessary when the signing-key is absent. The weakness is classified as CWE-287 (Improper Authentication).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of ownCloud ownCloud are affected?

BRANCHAFFECTEDFIXED

Is CVE-2023-49105 being exploited?

CISA added CVE-2023-49105 to the Known Exploited Vulnerabilities catalog on 2026-08-27, and U.S. federal agencies were required to address it by 2026-08-30. Public exploit code is available.

How to fix CVE-2023-49105

  1. Follow ownCloud vendor guidance and mitigations immediately if published.
  2. Restrict internet exposure of ownCloud instances and block access to the application from untrusted networks.
  3. Require signing-keys or disable acceptance of pre-signed URLs for user accounts that lack a signing-key, if configurable.
  4. Monitor access logs and file-change events for unexpected reads, modifications, or deletions and investigate anomalies.

Frequently asked questions

Is CVE-2023-49105 being actively exploited?

CISA added CVE-2023-49105 to the Known Exploited Vulnerabilities catalog on 2026-08-27, and U.S. federal agencies were required to remediate it by 2026-08-30.

Which ownCloud versions are affected by CVE-2023-49105?

Third-party reporting indicates ownCloud releases starting at 10.6.0 through versions prior to 10.13.1 are affected.

Is there a patch for CVE-2023-49105?

No vendor patch is listed in the provided facts; apply vendor mitigations and restrict exposure until a patch is available.

Does CVE-2023-49105 require authentication?

No authentication is required when the victim account has no signing-key configured and pre-signed URLs are improperly accepted.

References