Threat+Constellation
Live UTC
← Incidents
INCIDENT 302Exploited vulnerabilityHIGH CONFIDENCESourced

CVE-2023-49105 added to CISA KEV: ownCloud Improper Authentication Vulnerability

ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. Product: ownCloud ownCloud. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product i…

Last evidence update
27 AUG 2026 · 00:00 UTC
Source count
2
Status
high confidence
CVE-2023-49105
Observation history

How this record has evolved as evidence accumulated.

28 AUG · 05:27 UTC
Initial report
28 AUG · 05:27 UTC
Second independent source
28 AUG · 05:27 UTC
Confidence upgraded
28 AUG · 05:27 UTC
Status changed
Evidence
Related incidents