Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: webdav (1 article)Clear

CISA flags exploited ownCloud flaw that lets attackers read and delete files

CISA added a critical ownCloud flaw to its exploited-vulnerabilities catalog after attackers used it to steal data from a research organization. Tracked as CVE-2023-49105 and scored 9.8, the WebDAV authentication-bypass bug lets an unauthenticated attacker who knows a victim's username read, modify, or delete that user's files when no signing key is configured, which is the platform's default. Disclosed back in November 2023, it affects ownCloud Server core versions 10.6.0 through 10.13.0 and was fixed in 10.13.1, yet unpatched instances remain exposed nearly two years later. Public exploit code exists, and CISA set a short deadline for federal agencies, underscoring that long-standing self-hosted flaws keep getting weaponized.

Check
Upgrade ownCloud Server to 10.13.1 or later now, or configure a signing key as a mitigation, and review WebDAV access logs for unusual file reads, changes, or deletions.
Affected
Organizations running ownCloud Server 10.6.0 through 10.13.0 without a signing key, the default (CVE-2023-49105); an unauthenticated attacker knowing a username can read, alter, or delete that user's files, and exploitation is active.
Fix
Patch to 10.13.1, set a signing key, restrict and monitor exposed WebDAV services, investigate for unauthorized file access or deletion, and treat any long-unpatched ownCloud instance as a likely target.