OwnCloud has released security updates to address CVE-2023-49105. CISA urges organizations to apply the patches immediately. Federal agencies must remediate or mitigate the vulnerability within the defined timeframe. Organizations should update to the latest patched version of ownCloud to prevent unauthorized access and data exfiltration.
Quick answers
What is CVE-2023-49105?
OwnCloud has released security updates to address CVE-2023-49105. CISA urges organizations to apply the patches immediately. Federal agencies must remediate or mitigate the vulnerability within the defined timeframe. Organizations should update to the latest patched version of ownCloud to prevent unauthorized access and data exfiltration.
How severe is CVE-2023-49105?
critical, CVSS 9.8
Is CVE-2023-49105 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2023-49105 be mitigated?
OwnCloud has released security updates to address CVE-2023-49105. CISA urges organizations to apply the patches immediately. Federal agencies must remediate or mitigate the vulnerability within the defined timeframe. Organizations should update to the latest patched version of ownCloud to prevent unauthorized access and data exfiltration.
CVSS
9.8
Vendor
ownCloud
Published
Sep 30, 2026 · 08:42
Patch
Unknown / not confirmed
Affected products
ownCloud
Mitigation
OwnCloud has released security updates to address CVE-2023-49105. CISA urges organizations to apply the patches immediately. Federal agencies must remediate or mitigate the vulnerability within the defined timeframe. Organizations should update to the latest patched version of ownCloud to prevent unauthorized access and data exfiltration.
On August 27, 2026, CISA added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. The newly listed flaws are CVE-2023-49105 (ownCloud Improper Authentication), CVE-2026-53362 (Linux Kernel Unspecified), and CVE-2026-66384 (JFrog Artifactory Improper Limitation of a Pathname). CISA also reminded organizations of Binding Operational Directive 26-04, which mandates rapid remediation of KEV-listed vulnerabilities on publicly exposed federal assets and requires pre-patch compromise checks.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the critical vulnerability CVE-2023-49105, affecting ownCloud, to its Known Exploited Vulnerabilities (KEV) catalog. Reports indicate a Chinese-speaking threat actor weaponized the flaw to target a nuclear research body in the Philippines, with the aim of stealing sensitive nuclear records. The vulnerability carries a CVSS score of 9.8. CISA and ownCloud urge organizations to apply patches immediately to mitigate active exploitation in the wild.