CVE-2023-49105

Executive Summary

CVE-2023-49105 affects ownCloud core versions 10.6.0‑10.13.0. If a victim’s username is known and no signing‑key is set, attackers can use pre‑signed URLs to read, modify, or delete any file without authentication. The vulnerability is actively exploited in the wild (CISA KEV).


Authoritative CVE Metadata - CVSS Base Score: 9.8 (CRITICAL) - Published: 2023-11-21T22:15:08.613 - Last Modified: 2026-08-28T12:21:09.753

[!CAUTION] Known Exploited Vulnerability: YES (CISA KEV Added: 2026-08-27)

Original Description: An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0.

"He who knows, does not speak. He who speaks, does not know."

— Lao Tzu
Source: NVD