[KEV] CVE-2023-49105 -- CVSS 0.0 Vulnerability Briefing
[KEV] CVE-2023-49105 | CVSS 0.0 (Low) | Exploit: Operational
What Is It
CVE-2023-49105 is an improper authentication vulnerability in ownCloud that affects file access within ownCloud deployments.
Technical Detail
The flaw permits an unauthenticated attacker who knows a victim username to access that victim's files when the victim does not have a signing key configured. Exploitation is an authentication bypass, not remote code execution. A successful attacker can access, modify, or delete files belonging to the affected user.
Exploitation Status
CISA has confirmed active exploitation in the wild. Exploit maturity is assessed as Operational, meaning working exploitation capability is available and has been used in real-world intrusion activity.
Who Is Targeting This
Confirmed (ATTAX-verified): UNC3886 (China, nation-state), FIN13 (origin not specified, motivation unknown), and Magic Hound (Iran, nation-state). Reported (research-inferred): MAGICHOUND and EMBERBEAR.
What To Do
Prioritize remediation of internet-accessible ownCloud deployments and apply the vendor-provided security update or mitigation for CVE-2023-49105. Identify accounts without configured signing keys and review their file-access history for unexpected reads, modifications, deletions, or access from unfamiliar source addresses. CISA requires federal civilian executive branch agencies to patch by September 17, 2026, or apply mitigations where patching is not possible.