Skip to main content
QUIETLYTIC
Vulnerability

ownCloud Authentication Bypass (CVE-2023-49105)

CVE-2023-49105 is a CVSS 9.8 authentication bypass in ownCloud core allowing unauthenticated file access via pre-signed URLs, confirmed exploited per CISA KEV.

CVE-2023-49105
Threat Level
CRITICAL
CVSS
9.8
Status
Active Exploitation
Confidence
High
Affected Products
ownCloud, ownCloud core (10.6.0 through before 10.13.1)

CVE-2023-49105 carries a CVSS 3.1 base score of 9.8 against ownCloud, a self-hosted file-sync-and-share platform. NVD classifies it as CWE-287 (Improper Authentication) — a classification independently corroborated by CISA’s own KEV entry, which lists the same weakness. CISA added this CVE to its Known Exploited Vulnerabilities catalog on August 27, 2026, confirming real-world exploitation directly, not through a single-source vendor report.

Because CISA KEV itself is the authoritative source for exploitation status, this CVE carries high confidence on that point — a different evidentiary footing than the VulnCheck-only CVEs elsewhere in our recent coverage. CISA KEV listing also means the Binding Operational Directive 26-04 remediation obligation applies to in-scope federal agencies for this CVE, per CISA’s own mitigation guidance in our source data.

What the flaw is

NVD’s description is specific about the precondition and mechanism: ownCloud’s core component, before version 10.13.1, accepts pre-signed URLs for file access even when the file owner has no signing key configured. Pre-signed URL schemes are meant to let a server generate a time-limited, cryptographically-verifiable link to a specific resource without requiring the recipient to authenticate — the security of the scheme rests entirely on that signature being checked. NVD states that when a targeted user has never configured a signing key, ownCloud accepts the pre-signed URL anyway, effectively skipping the check the whole mechanism depends on.

The practical requirement, per NVD, is that the attacker know the target’s username — no password, session token, or other credential is needed. With that single piece of information, NVD states an attacker can access, modify, or delete any file belonging to that user without authentication. NVD notes the earliest affected version as 10.6.0, giving the vulnerability a multi-year window before its 2023 disclosure.

Evidence and confidence

  • High confidence — exploitation status, sourced directly from CISA KEV, which our evidence model treats as an authoritative single source for this specific field.
  • High confidence — the CWE-287 classification, independently corroborated by both NVD and CISA KEV.
  • Medium confidence — the CVSS 9.8 score and vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), which trace to NVD alone in our current ingestion.
  • Unknown-leaning — FIRST’s EPSS model scores this CVE unusually high for our recent KEV batches: 0.43205, a 98.65th percentile score — meaning FIRST’s model places this among the small fraction of all scored CVEs most likely to see exploitation, independent of and consistent with the CISA KEV listing itself.

No field is in conflict between our two sources. Our data carries no structured fixed-version field beyond NVD’s statement that the issue is fixed in 10.13.1.

Why this matters

This CVE was disclosed in November 2023 and only added to CISA’s KEV catalog in August 2026 — nearly three years later. A KEV addition on old, previously-patched software is not evidence the flaw is newly discovered; it typically reflects newly observed exploitation of long-unpatched deployments, which is consistent with a self-hosted file-sharing platform that, unlike SaaS software, depends on individual operators actually applying updates rather than a vendor pushing them centrally.

The evidence here is unusually strong for a KEV-driven advisory: CISA’s own listing, independent CWE corroboration, and a 98.65th-percentile EPSS score all point the same direction. For any organization running self-hosted ownCloud core below 10.13.1, this is one of the more solidly evidenced patch-priority cases in our recent coverage, and BOD 26-04’s remediation obligation genuinely applies for in-scope federal agencies.

Frequently Asked Questions

What is CVE-2023-49105? A CVSS 9.8 authentication bypass (CWE-287) in ownCloud core before version 10.13.1, allowing an attacker who knows a victim’s username to access, modify, or delete that user’s files without authentication, via a pre-signed URL accepted despite no signing key being configured.

Is CVE-2023-49105 being actively exploited? Yes, per CISA’s own Known Exploited Vulnerabilities catalog, which added this CVE on August 27, 2026. This is a higher-confidence exploitation claim than a VulnCheck-only listing, since CISA KEV is treated as an authoritative source in our evidence model.

Does this create a federal patching deadline? Yes. CISA KEV listing means Binding Operational Directive 26-04’s remediation timeline applies to in-scope federal agencies for this CVE.

Do I need the victim’s password to exploit this? No. NVD’s description states only the victim’s username is required — no password, session, or other credential.

Which version fixes this? NVD states the issue is fixed in ownCloud core 10.13.1. The affected range begins at version 10.6.0.

Why is a 2023 CVE showing up in a 2026 KEV feed? CISA added it to its Known Exploited Vulnerabilities catalog in August 2026 — years after initial disclosure — which typically reflects newly observed exploitation of deployments that were never patched, not a new vulnerability.


Severity, vector, weakness classification, mechanism, and fixed version sourced from the National Vulnerability Database record for CVE-2023-49105 and CISA’s Known Exploited Vulnerabilities catalog entry, both of which independently classify the weakness as CWE-287. ownCloud’s own security advisory is linked from NVD’s record: ownCloud pre-signed URL authentication bypass advisory. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 CISA Known Exploited Vulnerabilities (KEV) Catalog

Related intelligence


Analyst tools