Vulnerability
Published 2026-08-27
Verified 2026-09-19
ownCloud WebDAV pre-signed URL authentication bypass (CVE-2023-49105)
ownCloud core before 10.13.1 accepts pre-signed WebDAV URLs even when the file owner has no signing-key configured (the default). If the victim username is known, an unauthenticated attacker can access, modify, or delete any of that user's files. ownCloud rates CVSS 9.8. Fixed in 10.13.1 by denying pre-signed URLs when no signing-key is set. Patch, then review access logs for unexpected WebDAV activity.
- Product
- ownCloud core
- Versions
- 10.6.0 through 10.13.0
- CVSS
- (CVSS 3.1, ownCloud)
CVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:U/UI:N - Exploited in Australia?
- unknown
- Patch to
- 10.13.1 or later
Primary: ownCloud advisory · Vendor: NVD · CVE: CVE-2023-49105
