๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2023-49105: ownCloud Improper Authentication Vulnerability
Summary
ownCloud has an authentication bypass vulnerability (CVE-2023-49105) that lets attackers access, modify, or delete files without a password if they know the victim's username and the victim hasn't set up a signing-key (a cryptographic credential that verifies identity). This flaw is actively being exploited by real attackers.
Solution / Mitigation
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA's BOD 26-04 Prioritizing Security Updates Based on Risk guidance. Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Vulnerability Details
EPSS: 11.1%
Yes
๐ฅ Actively Exploited
August 26, 2026
Classification
Original source: https://nvd.nist.gov/vuln/detail/CVE-2023-49105
First tracked: August 27, 2026 at 02:01 PM
Classified by LLM (prompt v3) ยท confidence: 95%