CRITICAL🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2023-49105

CVSS 9.8v3.1pub. 2023-11-21upd. 2026-08-28

An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0.

🤖 AI Analysis
How it works

The vulnerability results from improper handling of pre-signed URLs in the WebDAV API. The system accepts requests signed with a pre-signed URL even when the file owner does not have a signing-key configured. An attacker can craft such a request by providing only the known login of the victim and gain full access to their resources without providing a password or authentication token.

Impact

An attacker can without authentication read, modify, or permanently delete any files belonging to a user whose username is known to them — resulting in complete compromise of data confidentiality, integrity, and availability.

Mitigation & patch

Update ownCloud Server to version 10.13.1 or later. As a workaround, you can configure a signing-key for each user account. Details in the vendor's official security advisory: https://owncloud.com/security-advisories/webdav-api-authentication-bypass-using-pre-signed-urls/

Who is affected

ownCloud Server versions 10.6.0 through 10.13.0 (versions before 10.13.1)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Owncloud Server

    APP
    Owncloud
    10.6.0 – 10.13.1 (excl.)

CISA KEV — detailsi

Vendori
ownCloud
Producti
ownCloud
Added to KEVi
August 27, 2026
Remediation deadline (US Federal)i
August 30, 2026(overdue)
Required action (CISA)i

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CISA descriptioni

ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 30 sierpnia 2026
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2014-2052CRITICAL9.8PL ✓same product

XXE w Zend Framework umożliwia odczyt plików w ownCloud Server

CVE-2016-1499HIGH8.5same product

ownCloud Server before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2 allow remote authenticated users to ...

CVE-2015-7699HIGH9.0same product

The files_external app in ownCloud Server before 7.0.9, 8.0.x before 8.0.7, and 8.1.x before 8.1.2 allows remo...

CVE-2015-6500HIGH7.5same product

Directory traversal vulnerability in ownCloud Server before 8.0.6 and 8.1.x before 8.1.1 allows remote authent...

CVE-2015-4716HIGH10.0same product

Directory traversal vulnerability in the routing component in ownCloud Server before 7.0.6 and 8.0.x before 8....