CISA added a critical ownCloud flaw to its exploited-vulnerabilities catalog after attackers used it to steal data from a research organization. Tracked as CVE-2023-49105 and scored 9.8, the WebDAV authentication-bypass bug lets an unauthenticated attacker who knows a victim's username read, modify, or delete that user's files when no signing key is configured, which is the platform's default. Disclosed back in November 2023, it affects ownCloud Server core versions 10.6.0 through 10.13.0 and was fixed in 10.13.1, yet unpatched instances remain exposed nearly two years later. Public exploit code exists, and CISA set a short deadline for federal agencies, underscoring that long-standing self-hosted flaws keep getting weaponized.