Junglewise Threat Intelligence

CVE-2023-49105: ownCloud improper authentication vulnerability

CVE-2023-49105 · Severity: critical · Exploited in the wild · Published 2026-08-27

Executive brief

ownCloud is a file synchronization and sharing platform used by organizations to store and collaborate on documents. This vulnerability allows attackers to access, modify, or delete files belonging to any user without needing to log in, provided they know the target user's username and that user has not configured signing keys. This poses a critical risk to data confidentiality, integrity, and availability for all ownCloud users.

Technical details

ownCloud contains an improper authentication flaw (CWE-287) in its file access control mechanism. The vulnerability allows unauthenticated attackers to interact with user files when the target user's username is known and no signing-key protection is enabled. The attack vector is network-based and does not require user interaction or existing authentication. An attacker can fully compromise file confidentiality and integrity by accessing, modifying, or deleting victim files. The vulnerability has been observed in active exploitation in the wild, indicating patch deployment should be prioritized immediately.

Affected products

  • ownCloud

Timeline

  • 2026-08-27: disclosed
  • exploited: Exploited in the wild

Related threats