CVE-2023-49105 shows how an older ownCloud vulnerability can remain an active enterprise risk, with CISA KEV listing following exploitation linked to sensitive data theft.
The WebDAV flaw can let unauthenticated attackers access, modify, or delete files when specific signing-key and username conditions are met.
Organizations should patch affected ownCloud deployments, investigate suspicious WebDAV activity, identify exposed data, and rotate compromised credentials, keys, or secrets.
Hexnode XDR can support follow-on endpoint investigation and response, while Hexnode UEM can help manage patching and patch compliance across supported endpoints.
An ownCloud vulnerability disclosed in late 2023 has returned to the spotlight after researchers linked it to the theft of sensitive nuclear research data.
CISA added CVE-2023-49105 to its Known Exploited Vulnerabilities (CISA KEV) catalog on August 27, 2026. The vulnerability affects ownCloud Server and can allow unauthenticated attackers to access, modify or delete files under specific conditions. CISA set August 30, 2026, as the remediation deadline for affected federal civilian agencies.
The incident demonstrates why organizations cannot treat older vulnerabilities as low-priority simply because patches have existed for years. Internet-facing collaboration platforms can hold sensitive documents, credentials and encryption material that make them valuable targets long after disclosure.
How does CVE-2023-49105 bypass ownCloud authentication?
CVE-2023-49105 is a critical vulnerability in ownCloud’s WebDAV API involving pre-signed URLs. It carries a CVSS v3.1 score of 9.8 and affects ownCloud core versions 10.6.0 through 10.13.0.
The vulnerability becomes exploitable when an attacker knows a victim’s username and that user does not have a signing key configured. Under those conditions, ownCloud can accept pre-signed URLs without properly authenticating the requester. An attacker can consequently access, modify or delete the victim’s files.
That level of access creates a significant data theft risk for organizations using vulnerable ownCloud deployments to store business, government or research information.
ownCloud addressed the issue by preventing users from using pre-signed URLs when administrators have not configured a signing key. The vendor subsequently advised affected organizations to upgrade to ownCloud Server 10.13.3 or apply the specific patch available to subscription customers.
How was the ownCloud vulnerability exploited?
Recent threat research connected CVE-2023-49105 with an intrusion targeting a Philippine nuclear research organization.
Researchers attributed the activity to a suspected Chinese-speaking operator. Evidence recovered from attacker-controlled infrastructure indicated that the actor used the ownCloud flaw to forge pre-signed WebDAV URLs, impersonate accounts, enumerate directories and retrieve files without valid credentials.
The exposed material reportedly included nuclear records, personnel information and credential-related files. Reports on the recovered intrusion data also identified sensitive material such as BitLocker keys and KeePass databases.
The presence of credential stores and encryption-related information makes credential exposure an important secondary concern. Attackers can continue to exploit stolen credentials or secrets even after organizations patch the original vulnerability.
CISA’s decision to place CVE-2023-49105 in the CISA KEV catalog confirms that organizations should treat the vulnerability as an active exploitation concern rather than a theoretical weakness.
Featured Resource
Cybersecurity kit
Access essential cybersecurity resources to strengthen security, reduce risk, and improve cyber resilience.
What should organizations do about CVE-2023-49105?
Organizations running ownCloud Server should first determine whether vulnerable versions remain in their environments. Affected deployments should be upgraded according to ownCloud’s remediation guidance.
Security teams should also treat patching as only one part of the response. If a vulnerable instance was internet-accessible, they should investigate whether exploitation occurred before remediation.
That assessment should include reviewing WebDAV and application logs for suspicious requests, unexpected directory enumeration and unusual file retrieval. Teams should also identify accounts and sensitive files accessible through the affected deployment.
If exposed material includes passwords, keys, tokens or credential databases, organizations should rotate affected secrets rather than assuming patching has eliminated the downstream risk.
How can Hexnode support endpoint investigation and response?
For organizations investigating possible follow-on activity, Hexnode XDR provides endpoint-focused visibility for detecting, investigating and responding to security threats. Its Incidents view consolidates threat detections and contextual information, while threat incidents can include process and telemetry data mapped against the MITRE ATT&CK framework.
This visibility can help defenders examine suspicious activity on monitored endpoints after a suspected ownCloud compromise. Hexnode XDR surfaces activity associated with MITRE ATT&CK tactics such as Credential Access, Discovery, Lateral Movement, Collection and Exfiltration. Analysts can use this context to understand how endpoint behavior fits within the wider attack chain.
Because attackers exfiltrated credentials and BitLocker keys, Hexnode XDR becomes essential for detecting attempts to use those stolen secrets on monitored endpoints.
When Hexnode XDR identifies malicious endpoint activity, administrators can investigate process relationships and take response actions such as killing a malicious process, quarantining a file or isolating an affected endpoint.
However, ownCloud Server is a Linux-hosted web application. Organizations must patch and remediate the vulnerable ownCloud deployment directly according to the vendor’s guidance, outside endpoint management workflows.
Hexnode UEM complements this server-side remediation by helping administrators manage patches and monitor patch compliance across supported Windows and macOS client endpoints. For Windows endpoints, administrators can also define automated patch workflows using criteria such as CVE identifiers and severity.
Together, server remediation, endpoint patch compliance and XDR investigation can help organizations address the original ownCloud vulnerability while monitoring connected endpoints for follow-on activity.
FAQs
Why does CISA add a vulnerability to the KEV catalog years after disclosure?
CISA can add a vulnerability to the KEV catalog when evidence shows that attackers are actively exploiting it, regardless of when researchers originally disclosed it. CVE-2023-49105 demonstrates why organizations should prioritize vulnerabilities based on exploitation risk rather than age alone.
Is patching CVE-2023-49105 enough after a vulnerable ownCloud server was exposed to the internet?
No. Organizations should patch the vulnerable deployment and investigate whether exploitation occurred before remediation. Reviewing WebDAV and application logs, suspicious file retrieval and potentially exposed accounts can help determine whether the incident requires a broader response.
What credentials and secrets should organizations rotate after suspected ownCloud exploitation?
Organizations should identify passwords, keys, tokens, credential databases and other sensitive secrets that may have been accessible through the compromised deployment. Any potentially exposed credentials or secrets should be rotated because patching the original vulnerability does not eliminate risks created by prior data theft.
Old vulnerabilities can still create new breaches
CVE-2023-49105 shows why vulnerability age is a poor substitute for actual risk. The flaw was disclosed in 2023, yet its addition to CISA KEV in 2026 underscores the continuing danger posed by vulnerable internet-facing systems.
Organizations running ownCloud should follow the vendor’s remediation guidance, examine potentially exposed systems for signs of compromise and rotate sensitive credentials or secrets where necessary.
Beyond remediating the ownCloud server directly, security teams should investigate connected endpoints for subsequent malicious activity. Combining platform-specific server remediation with endpoint patch compliance and XDR investigation can help organizations determine whether stolen credentials or secrets have enabled a broader security incident.
Strengthen Response to Exploited Vulnerabilities
Investigate endpoint activity, contain active threats, and strengthen enterprise response with Hexnode XDR.
Content writer at Hexnode. Fueled by good coffee and the occasional cat cuddle, I enjoy crafting content that informs, connects, and resonates. Nothing excites me more than knowing my words have been read, appreciated, and maybe even bookmarked.