CISA Adds ownCloud CVE-2023-49105 to Actively Exploited Vulnerabilities
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the CVE-2023-49105 vulnerability in ownCloud Server to its Known Exploited Vulnerabilities catalog. Unpatched instances may expose user files to unauthorized reading, modification, or deletion.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added ownCloud CVE-2023-49105 to its Known Exploited Vulnerabilities (KEV) catalog, covering flaws it records as being exploited in the wild. This is an older WebDAV API vulnerability in ownCloud Server, but the new listing is a clear signal for administrators to prioritize finding and updating unpatched systems.
The flaw may allow an unauthenticated attacker to access another user’s files and potentially modify or delete them. The conditions are knowledge of the victim’s username and the absence of a configured signing-key. According to ownCloud, the signing-key was not configured by default.
What ownCloud CVE-2023-49105 Enables
The vulnerability affects authentication in the WebDAV API when pre-signed URLs are used. In the affected configuration, an attacker may bypass identity verification if they know the target’s username. This may result in unauthorized reading, modification, or deletion of user files.
ownCloud states that the impact affects the product core in versions 10.6.0 through 10.13.0. The risk therefore primarily concerns internet-accessible instances in this range that have not been patched and do not have a signing-key configured. In its KEV entry, CISA explicitly assesses the flaw as exploited, so this is not merely a theoretically disclosed security issue.
A Fix Is Available
The vendor recommends updating ownCloud to version 10.13.3. Customers with support may also deploy a specific patch provided through ownCloud support. Administrators should first verify the deployed core version, the service’s internet exposure, and the signing-key configuration status, then apply the recommended fix without unnecessary delay.
- Identify ownCloud Server installations with core versions 10.6.0 through 10.13.0.
- Prioritize reviewing instances accessible from the internet.
- Update to ownCloud 10.13.3 or use the patch intended for support customers.
- Check whether a signing-key is configured, but do not treat this as a replacement for the vulnerability fix.
Why the KEV Listing Matters
CISA’s KEV catalog serves as an authoritative overview of vulnerabilities with confirmed exploitation. For ownCloud CVE-2023-49105, the addition increases the urgency of remediation: the potential impact concerns not only service availability but directly the confidentiality and integrity of stored data.
However, the information provided does not identify a specific current campaign, the attacker’s identity, the number of affected instances, or the extent of any potential damage. It is also not confirmed whether the KEV listing is connected to a new wave of attacks or to historical incidents verified later.
Further developments will depend on whether CISA, ownCloud, national CERT teams, or affected organizations publish technical details about exploitation, recommendations for detecting compromise, or confirmed incidents.
Sources
- CISA Known Exploited Vulnerabilities Catalog – Confirms the addition of CVE-2023-49105 to KEV and CISA’s assessment that the vulnerability was exploited.
- ownCloud – WebDAV Api Authentication Bypass using Pre-Signed URLs – Confirms the flaw’s technical conditions, affected core versions 10.6.0 through 10.13.0, and the remediation approach.
- ownCloud – Immediate Action Required: Critical Security Updates for ownCloud – Confirms the recommendation to update to ownCloud 10.13.3 or use the patch available through support.
Verified and updated: 27. 08. 2026 19:53



