Exploited Vulnerabilities Daily
🌐 English

← All new entries

CVE-2023-49105: ownCloud ownCloud

ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured.

Vendor
ownCloud
Product
ownCloud
Vulnerability
ownCloud Improper Authentication Vulnerability
Date added
Aug 27, 2026
CISA due date (U.S. federal agencies)
Aug 30, 2026
Known ransomware campaign use
Unknown
Weakness (CWE)
CWE-287

References

This site summarizes CISA's catalog for information only. It is not security advice — follow your vendor's guidance and official advisories.

Last updated: · Catalog version 2026.10.02