{"id":1305,"date":"2026-09-01T13:12:20","date_gmt":"2026-09-01T07:42:20","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1305"},"modified":"2026-09-03T12:35:29","modified_gmt":"2026-09-03T07:05:29","slug":"owncloud-kev-exploitation-turns-webdav-defaults-into-nuclear-research-data-theft","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/owncloud-kev-exploitation-turns-webdav-defaults-into-nuclear-research-data-theft\/","title":{"rendered":"ownCloud KEV Exploitation Turns WebDAV Defaults Into Nuclear Research Data Theft"},"content":{"rendered":"<p>An ownCloud vulnerability disclosed in late 2023 has returned to the spotlight after researchers linked it to the theft of sensitive nuclear research data.<\/p>\n<p>CISA added CVE-2023-49105 to its Known Exploited Vulnerabilities (CISA KEV) catalog on August 27, 2026. The vulnerability affects ownCloud Server and can allow unauthenticated attackers to access, modify or delete files under specific conditions. CISA set August 30, 2026, as the remediation deadline for affected federal civilian agencies.<\/p>\n<p>The incident demonstrates why organizations cannot treat older vulnerabilities as low-priority simply because patches have existed for years. Internet-facing collaboration platforms can hold sensitive documents, credentials and encryption material that make them valuable targets long after disclosure.<\/p>\n<p><center>    \t\t<!-- button style scb6aaa006dc095ba618bc1777be3a12f2a -->\r\n    \t\t<style>\r\n    \t\t\t.scb6aaa006dc095ba618bc1777be3a12f2a, a.scb6aaa006dc095ba618bc1777be3a12f2a{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: ;\r\n    \t\t\t}\r\n    \t\t\t.scb6aaa006dc095ba618bc1777be3a12f2a:hover, a.scb6aaa006dc095ba618bc1777be3a12f2a:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #323232;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/uem\/\" class=\"ht-shortcodes-button scb6aaa006dc095ba618bc1777be3a12f2a  hn-cta__blogs--inline-button \" id=\"\" style=\"\" >\r\n    \t\tStrengthen Response to Exploited Vulnerabilities with Hexnode<\/a>\r\n    \t\t<\/center><\/p>\n<h2>How does CVE-2023-49105 bypass ownCloud authentication?<\/h2>\n<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2023-49105?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=cisa_kev\" target=\"_blank\" rel=\"nofollow noopener\">CVE-2023-49105<\/a> is a critical vulnerability in ownCloud&#8217;s WebDAV API involving pre-signed URLs. It carries a CVSS v3.1 score of 9.8 and affects ownCloud core versions 10.6.0 through 10.13.0.<\/p>\n<p>The vulnerability becomes exploitable when an attacker knows a victim&#8217;s username and that user does not have a signing key configured. Under those conditions, ownCloud can accept pre-signed URLs without properly authenticating the requester. An attacker can consequently access, modify or delete the victim&#8217;s files.<\/p>\n<p>That level of access creates a significant data theft risk for organizations using vulnerable ownCloud deployments to store business, government or research information.<\/p>\n<p>ownCloud addressed the issue by preventing users from using pre-signed URLs when administrators have not configured a signing key. The vendor subsequently advised affected organizations to upgrade to ownCloud Server 10.13.3 or apply the specific patch available to subscription customers.<\/p>\n<h2>How was the ownCloud vulnerability exploited?<\/h2>\n<p>Recent threat research connected CVE-2023-49105 with an intrusion targeting a Philippine nuclear research organization.<\/p>\n<p>Researchers attributed the activity to a suspected Chinese-speaking operator. Evidence recovered from attacker-controlled infrastructure indicated that the actor used the ownCloud flaw to forge pre-signed WebDAV URLs, impersonate accounts, enumerate directories and retrieve files without valid credentials.<\/p>\n<p>The exposed material reportedly included nuclear records, personnel information and credential-related files. Reports on the recovered intrusion data also identified sensitive material such as BitLocker keys and KeePass databases.<\/p>\n<p>The presence of credential stores and encryption-related information makes credential exposure an important secondary concern. Attackers can continue to exploit stolen credentials or secrets even after organizations patch the original vulnerability.<\/p>\n<p>CISA&#8217;s decision to place CVE-2023-49105 in the CISA KEV catalog confirms that organizations should treat the vulnerability as an active exploitation concern rather than a theoretical weakness.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cybersecurity-kit.webp?format=webp\" class=\"resource-box__image\" alt=\"cybersecurity-kit\" loading=\"lazy\" srcset=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cybersecurity-kit.webp?format=webp 960w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cybersecurity-kit-300x225.webp?format=webp 300w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cybersecurity-kit-768x576.webp?format=webp 768w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cybersecurity-kit-133x100.webp?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"cybersecurity-kit\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured Resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Cybersecurity kit\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Access essential cybersecurity resources to strengthen security, reduce risk, and improve cyber resilience.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/resource-kits\/cybersecurity-kit\/'>\n                            Download the Resource Kit\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>What should organizations do about CVE-2023-49105?<\/h2>\n<p>Organizations running ownCloud Server should first determine whether vulnerable versions remain in their environments. Affected deployments should be upgraded according to ownCloud&#8217;s remediation guidance.<\/p>\n<p>Security teams should also treat patching as only one part of the response. If a vulnerable instance was internet-accessible, they should investigate whether exploitation occurred before remediation.<\/p>\n<p>That assessment should include reviewing WebDAV and application logs for suspicious requests, unexpected directory enumeration and unusual file retrieval. Teams should also identify accounts and sensitive files accessible through the affected deployment.<\/p>\n<p>If exposed material includes passwords, keys, tokens or credential databases, organizations should rotate affected secrets rather than assuming patching has eliminated the downstream risk.<\/p>\n<h2>How can Hexnode support endpoint investigation and response?<\/h2>\n<p>For organizations investigating possible follow-on activity, <a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a> provides endpoint-focused visibility for detecting, investigating and responding to security threats. Its Incidents view consolidates threat detections and contextual information, while threat incidents can include process and telemetry data mapped against the <a href=\"https:\/\/www.hexnode.com\/blogs\/mitre-attack-framework\/\">MITRE ATT&amp;CK<\/a> framework.<\/p>\n<p>This visibility can help defenders examine suspicious activity on monitored endpoints after a suspected ownCloud compromise. Hexnode XDR surfaces activity associated with MITRE ATT&amp;CK tactics such as Credential Access, Discovery, Lateral Movement, Collection and Exfiltration. Analysts can use this context to understand how endpoint behavior fits within the wider attack chain.<\/p>\n<p>Because attackers exfiltrated credentials and BitLocker keys, Hexnode XDR becomes essential for detecting attempts to use those stolen secrets on monitored endpoints.<\/p>\n<p>When Hexnode XDR identifies malicious endpoint activity, administrators can investigate process relationships and take response actions such as killing a malicious process, quarantining a file or isolating an affected endpoint.<\/p>\n<p>However, ownCloud Server is a Linux-hosted web application. Organizations must patch and remediate the vulnerable ownCloud deployment directly according to the vendor\u2019s guidance, outside endpoint management workflows.<\/p>\n<p>Hexnode UEM complements this server-side remediation by helping administrators manage patches and monitor patch compliance across supported Windows and macOS client endpoints. For Windows endpoints, administrators can also define automated patch workflows using criteria such as CVE identifiers and severity.<\/p>\n<p>Together, server remediation, endpoint patch compliance and XDR investigation can help organizations address the original ownCloud vulnerability while monitoring connected endpoints for follow-on activity.<\/p>\n<h3>FAQs<\/h3>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Why does CISA add a vulnerability to the KEV catalog years after disclosure?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>CISA can add a vulnerability to the KEV catalog when evidence shows that attackers are actively exploiting it, regardless of when researchers originally disclosed it. CVE-2023-49105 demonstrates why organizations should prioritize vulnerabilities based on exploitation risk rather than age alone.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Is patching CVE-2023-49105 enough after a vulnerable ownCloud server was exposed to the internet?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>No. Organizations should patch the vulnerable deployment and investigate whether exploitation occurred before remediation. Reviewing WebDAV and application logs, suspicious file retrieval and potentially exposed accounts can help determine whether the incident requires a broader response.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">What credentials and secrets should organizations rotate after suspected ownCloud exploitation?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Organizations should identify passwords, keys, tokens, credential databases and other sensitive secrets that may have been accessible through the compromised deployment. Any potentially exposed credentials or secrets should be rotated because patching the original vulnerability does not eliminate risks created by prior data theft.<\/p>\n<\/div><\/div><\/div>\n<h3>Old vulnerabilities can still create new breaches<\/h3>\n<p>CVE-2023-49105 shows why vulnerability age is a poor substitute for actual risk. The flaw was disclosed in 2023, yet its addition to CISA KEV in 2026 underscores the continuing danger posed by vulnerable internet-facing systems.<\/p>\n<p>Organizations running ownCloud should follow the vendor&#8217;s remediation guidance, examine potentially exposed systems for signs of compromise and rotate sensitive credentials or secrets where necessary.<\/p>\n<p>Beyond remediating the ownCloud server directly, security teams should investigate connected endpoints for subsequent malicious activity. Combining platform-specific server remediation with endpoint patch compliance and XDR investigation can help organizations determine whether stolen credentials or secrets have enabled a broader security incident.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Strengthen Response to Exploited Vulnerabilities<\/h5><p>Investigate endpoint activity, contain active threats, and strengthen enterprise response with Hexnode XDR.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Start Your Free Trial! <\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>An ownCloud vulnerability disclosed in late 2023 has returned to the spotlight after researchers linked&#8230;<\/p>\n","protected":false},"author":6,"featured_media":1372,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[19,21],"class_list":["post-1305","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cloud-and-saas","category-patch-management","product_category-extended-detection-and-response","tab_group-vulnerabilities"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>ownCloud CVE-2023-49105 Added to CISA KEV After Data Theft<\/title>\n<meta name=\"description\" content=\"CISA KEV lists ownCloud CVE-2023-49105 after active exploitation led to sensitive data theft. Learn the risks and enterprise response steps.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/owncloud-kev-exploitation-turns-webdav-defaults-into-nuclear-research-data-theft\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"ownCloud CVE-2023-49105 Added to CISA KEV After Data Theft\" \/>\n<meta property=\"og:description\" content=\"CISA KEV lists ownCloud CVE-2023-49105 after active exploitation led to sensitive data theft. Learn the risks and enterprise response steps.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/owncloud-kev-exploitation-turns-webdav-defaults-into-nuclear-research-data-theft\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-01T07:42:20+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-03T07:05:29+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/ownCloud-KEV-Exploitation-Turns-WebDAV-Defaults-Into-Nuclear-Research-Data-Theft.png?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Lily Anne\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Lily Anne\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/owncloud-kev-exploitation-turns-webdav-defaults-into-nuclear-research-data-theft\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/owncloud-kev-exploitation-turns-webdav-defaults-into-nuclear-research-data-theft\\\/\"},\"author\":{\"name\":\"Lily Anne\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/072b33718ec5df7cb7dbb9bae93044fa\"},\"headline\":\"ownCloud KEV Exploitation Turns WebDAV Defaults Into Nuclear Research Data Theft\",\"datePublished\":\"2026-09-01T07:42:20+00:00\",\"dateModified\":\"2026-09-03T07:05:29+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/owncloud-kev-exploitation-turns-webdav-defaults-into-nuclear-research-data-theft\\\/\"},\"wordCount\":1107,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/owncloud-kev-exploitation-turns-webdav-defaults-into-nuclear-research-data-theft\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ownCloud-KEV-Exploitation-Turns-WebDAV-Defaults-Into-Nuclear-Research-Data-Theft.png?format=webp\",\"articleSection\":[\"Cloud and SaaS\",\"Patch Management\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/owncloud-kev-exploitation-turns-webdav-defaults-into-nuclear-research-data-theft\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/owncloud-kev-exploitation-turns-webdav-defaults-into-nuclear-research-data-theft\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/owncloud-kev-exploitation-turns-webdav-defaults-into-nuclear-research-data-theft\\\/\",\"name\":\"ownCloud CVE-2023-49105 Added to CISA KEV After Data Theft\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/owncloud-kev-exploitation-turns-webdav-defaults-into-nuclear-research-data-theft\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/owncloud-kev-exploitation-turns-webdav-defaults-into-nuclear-research-data-theft\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ownCloud-KEV-Exploitation-Turns-WebDAV-Defaults-Into-Nuclear-Research-Data-Theft.png?format=webp\",\"datePublished\":\"2026-09-01T07:42:20+00:00\",\"dateModified\":\"2026-09-03T07:05:29+00:00\",\"description\":\"CISA KEV lists ownCloud CVE-2023-49105 after active exploitation led to sensitive data theft. Learn the risks and enterprise response steps.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/owncloud-kev-exploitation-turns-webdav-defaults-into-nuclear-research-data-theft\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/owncloud-kev-exploitation-turns-webdav-defaults-into-nuclear-research-data-theft\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/owncloud-kev-exploitation-turns-webdav-defaults-into-nuclear-research-data-theft\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ownCloud-KEV-Exploitation-Turns-WebDAV-Defaults-Into-Nuclear-Research-Data-Theft.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ownCloud-KEV-Exploitation-Turns-WebDAV-Defaults-Into-Nuclear-Research-Data-Theft.png?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"ownCloud KEV Exploitation Turns WebDAV Defaults Into Nuclear Research Data Theft\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/owncloud-kev-exploitation-turns-webdav-defaults-into-nuclear-research-data-theft\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"ownCloud KEV Exploitation Turns WebDAV Defaults Into Nuclear Research Data Theft\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/072b33718ec5df7cb7dbb9bae93044fa\",\"name\":\"Lily Anne\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"caption\":\"Lily Anne\"},\"description\":\"Content writer at Hexnode. Fueled by good coffee and the occasional cat cuddle, I enjoy crafting content that informs, connects, and resonates. Nothing excites me more than knowing my words have been read, appreciated, and maybe even bookmarked.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/lily-anne\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"ownCloud CVE-2023-49105 Added to CISA KEV After Data Theft","description":"CISA KEV lists ownCloud CVE-2023-49105 after active exploitation led to sensitive data theft. Learn the risks and enterprise response steps.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/owncloud-kev-exploitation-turns-webdav-defaults-into-nuclear-research-data-theft\/","og_locale":"en_US","og_type":"article","og_title":"ownCloud CVE-2023-49105 Added to CISA KEV After Data Theft","og_description":"CISA KEV lists ownCloud CVE-2023-49105 after active exploitation led to sensitive data theft. Learn the risks and enterprise response steps.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/owncloud-kev-exploitation-turns-webdav-defaults-into-nuclear-research-data-theft\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-01T07:42:20+00:00","article_modified_time":"2026-09-03T07:05:29+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/ownCloud-KEV-Exploitation-Turns-WebDAV-Defaults-Into-Nuclear-Research-Data-Theft.png?format=webp","type":"image\/png"}],"author":"Lily Anne","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Lily Anne","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/owncloud-kev-exploitation-turns-webdav-defaults-into-nuclear-research-data-theft\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/owncloud-kev-exploitation-turns-webdav-defaults-into-nuclear-research-data-theft\/"},"author":{"name":"Lily Anne","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/072b33718ec5df7cb7dbb9bae93044fa"},"headline":"ownCloud KEV Exploitation Turns WebDAV Defaults Into Nuclear Research Data Theft","datePublished":"2026-09-01T07:42:20+00:00","dateModified":"2026-09-03T07:05:29+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/owncloud-kev-exploitation-turns-webdav-defaults-into-nuclear-research-data-theft\/"},"wordCount":1107,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/owncloud-kev-exploitation-turns-webdav-defaults-into-nuclear-research-data-theft\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/ownCloud-KEV-Exploitation-Turns-WebDAV-Defaults-Into-Nuclear-Research-Data-Theft.png?format=webp","articleSection":["Cloud and SaaS","Patch Management"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/owncloud-kev-exploitation-turns-webdav-defaults-into-nuclear-research-data-theft\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/owncloud-kev-exploitation-turns-webdav-defaults-into-nuclear-research-data-theft\/","url":"https:\/\/www.hexnode.com\/threat-watch\/owncloud-kev-exploitation-turns-webdav-defaults-into-nuclear-research-data-theft\/","name":"ownCloud CVE-2023-49105 Added to CISA KEV After Data Theft","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/owncloud-kev-exploitation-turns-webdav-defaults-into-nuclear-research-data-theft\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/owncloud-kev-exploitation-turns-webdav-defaults-into-nuclear-research-data-theft\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/ownCloud-KEV-Exploitation-Turns-WebDAV-Defaults-Into-Nuclear-Research-Data-Theft.png?format=webp","datePublished":"2026-09-01T07:42:20+00:00","dateModified":"2026-09-03T07:05:29+00:00","description":"CISA KEV lists ownCloud CVE-2023-49105 after active exploitation led to sensitive data theft. Learn the risks and enterprise response steps.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/owncloud-kev-exploitation-turns-webdav-defaults-into-nuclear-research-data-theft\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/owncloud-kev-exploitation-turns-webdav-defaults-into-nuclear-research-data-theft\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/owncloud-kev-exploitation-turns-webdav-defaults-into-nuclear-research-data-theft\/#primaryimage","url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/ownCloud-KEV-Exploitation-Turns-WebDAV-Defaults-Into-Nuclear-Research-Data-Theft.png?format=webp","contentUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/ownCloud-KEV-Exploitation-Turns-WebDAV-Defaults-Into-Nuclear-Research-Data-Theft.png?format=webp","width":1340,"height":700,"caption":"ownCloud KEV Exploitation Turns WebDAV Defaults Into Nuclear Research Data Theft"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/owncloud-kev-exploitation-turns-webdav-defaults-into-nuclear-research-data-theft\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"ownCloud KEV Exploitation Turns WebDAV Defaults Into Nuclear Research Data Theft"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/072b33718ec5df7cb7dbb9bae93044fa","name":"Lily Anne","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","caption":"Lily Anne"},"description":"Content writer at Hexnode. Fueled by good coffee and the occasional cat cuddle, I enjoy crafting content that informs, connects, and resonates. Nothing excites me more than knowing my words have been read, appreciated, and maybe even bookmarked.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/lily-anne\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1305","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1305"}],"version-history":[{"count":5,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1305\/revisions"}],"predecessor-version":[{"id":1341,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1305\/revisions\/1341"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1372"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1305"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1305"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}