DIRAS TAKE
Urgent — CISA placed this vulnerability on the Known Exploited Vulnerabilities catalog with a tight remediation deadline, indicating rapid action is required for exposed systems.
What is CVE-2023-49105?
Unauthenticated attackers can read, alter, or remove files stored on ownCloud by exploiting a flaw that accepts pre-signed URLs even when an account has no signing-key configured; this issue is tracked as CVE-2023-49105. Reports show the problem exists in ownCloud releases beginning with 10.6.0 and affecting versions before 10.13.1. Exploitation requires only network access and knowledge of a valid username for the targeted account — no login or user interaction is necessary when the signing-key is absent. The weakness is classified as CWE-287 (Improper Authentication).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of ownCloud ownCloud are affected?
| BRANCH | AFFECTED | FIXED |
|---|
Is CVE-2023-49105 being exploited?
CISA added CVE-2023-49105 to the Known Exploited Vulnerabilities catalog on 2026-08-27, and U.S. federal agencies were required to address it by 2026-08-30. Public exploit code is available.
How to fix CVE-2023-49105
- Follow ownCloud vendor guidance and mitigations immediately if published.
- Restrict internet exposure of ownCloud instances and block access to the application from untrusted networks.
- Require signing-keys or disable acceptance of pre-signed URLs for user accounts that lack a signing-key, if configurable.
- Monitor access logs and file-change events for unexpected reads, modifications, or deletions and investigate anomalies.
Frequently asked questions
Is CVE-2023-49105 being actively exploited?
CISA added CVE-2023-49105 to the Known Exploited Vulnerabilities catalog on 2026-08-27, and U.S. federal agencies were required to remediate it by 2026-08-30.
Which ownCloud versions are affected by CVE-2023-49105?
Third-party reporting indicates ownCloud releases starting at 10.6.0 through versions prior to 10.13.1 are affected.
Is there a patch for CVE-2023-49105?
No vendor patch is listed in the provided facts; apply vendor mitigations and restrict exposure until a patch is available.
Does CVE-2023-49105 require authentication?
No authentication is required when the victim account has no signing-key configured and pre-signed URLs are improperly accepted.
References
- nvd.nist.gov/vuln/detail/CVE-2023-49105
- cve.org/CVERecord?id=CVE-2023-49105
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-49105
- owncloud.org/security
- owncloud.com/security-advisories/webdav-api-authentication-bypass-using-pre-signed-urls
- All ownCloud CVEs on CVE Radar
- CVEs published in September 2026