Vulnerability
Published 2026-08-27
Verified 2026-09-19

ownCloud WebDAV pre-signed URL authentication bypass (CVE-2023-49105)

ownCloud core before 10.13.1 accepts pre-signed WebDAV URLs even when the file owner has no signing-key configured (the default). If the victim username is known, an unauthenticated attacker can access, modify, or delete any of that user's files. ownCloud rates CVSS 9.8. Fixed in 10.13.1 by denying pre-signed URLs when no signing-key is set. Patch, then review access logs for unexpected WebDAV activity.

Product
ownCloud core
Versions
10.6.0 through 10.13.0
CVSS
(CVSS 3.1, ownCloud)
Exploited in Australia?
unknown
Patch to
10.13.1 or later

Primary: ownCloud advisory · Vendor: NVD · CVE: CVE-2023-49105

vulnerabilities