Home ยท Wiki ยท Vulnerabilities & CVEs
type: vulnerability ยท created: 2026-08-28 ยท updated: 2026-08-28 ยท tags: [cyber, vulnerability] ยท confidence: high ยท severity: high ยท affected_sectors: [technology, public sector] ยท au_impact: true

CVE-2023-49105

Summary

CVE-2023-49105 is a vulnerability in ownCloud characterised by improper authentication (an authentication bypass). It affects the ownCloud file-sync and sharing platform, which is widely used by organisations that prefer self-hosted file collaboration. CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog on 27 August 2026 based on evidence of active exploitation.

Technical detail

The flaw is an improper-authentication issue that allows an attacker without valid credentials to gain access to the platform or to act with elevated privileges. The authentication bypass mirrors an earlier attack pattern seen against ownCloud, meaning the abuse technique is already well understood by threat actors. Because ownCloud instances are commonly exposed to the internet to support remote file access and sharing, an unauthenticated path to the service carries a serious consequences risk of data exposure and lateral movement.

Significance

Inclusion on the KEV Catalog confirms that this vulnerability is being exploited in the wild, not merely theoretically vulnerable. US federal agencies are required to remediate under BOD timelines and to look for signs that the instance was already compromised before patching. The recurrence of the ownCloud attack pattern makes it a well-signalled risk that should be addressed promptly.

AU/NZ relevance

ownCloud is widely operated by Australian and New Zealand government agencies and universities for internally hosted file collaboration. Any internet-exposed ownCloud deployment served by Australian or New Zealand organisations should be patched and treated as a priority remediation item, and defenders should check logs for signs of pre-patch exploitation.