ZeroDayAlert

CVE-2023-49105: ownCloud Improper Authentication Vulnerability

ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured.

ownCloud ownCloud Added to KEV 2026-08-27 Federal due 2026-08-30 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

ownCloud deployments are vulnerable if users have not configured signing keys. An attacker who knows a victim's username can access, modify, or delete files without providing any credentials, provided no signing key is in place. The vulnerability affects both cloud-hosted and on-premises ownCloud instances where this authentication bypass condition exists.

How to check whether this touches you

  • Inventory ownCloud instances you operate or depend on, including version numbers and deployment type (self-hosted or cloud-managed).
  • Establish whether each instance is reachable from the internet or from untrusted networks; internal-only instances reduce immediate risk but do not eliminate it if lateral movement is possible.
  • Check the ownCloud administrative interface to determine how many user accounts lack a configured signing key; this is the prerequisite for exploitation.
  • Query logs for file access, modification, or deletion by accounts without valid session tokens, focusing on the period before you became aware of this vulnerability.

What to do

  1. Contact your ownCloud vendor or hosting provider immediately to confirm the patched version available to you and the timeline for application.
  2. Until patching is complete, require all user accounts to configure a signing key; document which accounts cannot do so and assess the sensitivity of their files.
  3. If patching is unavailable or significantly delayed, restrict network access to ownCloud to known, authenticated IP ranges and consider taking the service offline if files are highly sensitive.
  4. Enable and retain all authentication and file-operation logs at maximum verbosity for at least 90 days before patching; configure alerts for failed authentication attempts or file operations by unauthenticated sessions.
  5. Escalate to your security team and legal or compliance department if ownCloud is used to store regulated data (personal data, health records, financial information) or if it is internet-facing.

If you find you were exposed

Exploitation of this vulnerability could have occurred at any point before signing keys were enforced or before you became aware of the flaw. Review file-access and modification logs backdated to your earliest retention, focusing on operations by users without active sessions or with anomalous access patterns. If your deployment was internet-facing, assume a longer window of exposure and prioritise recovery of deleted or modified files from backups if available.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2023-49105 is being exploited. It cannot tell you whether ownCloud is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →