CVE-2023-49105 is a critical authentication bypass vulnerability in ownCloud server versions 10.6.0 through 10.13.0. An unauthenticated attacker can gain full access to a victim's files (read, modify, delete) if the victim's username is known and they lack a configured signing key, due to improper handling of pre-signed URLs. This vulnerability carries a CVSS score of 9.8 (Critical) with low attack complexity and no user interaction required, enabling complete compromise of data confidentiality, integrity, and availability. While not yet in CISA's KEV catalog, its high EPSS score (0.896) and active community discussion with available Nuclei templates indicate a high likelihood of exploitation. Media outlets have reported active exploitation of this flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.6.0, < 10.13.1CPE matchmatch criteria | cpe:2.3:a:owncloud:owncloud_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.