LATEST View all updates

ownCloud CVE-2023-49105: Check Affected Versions and Patch the Exploited Flaw

CVE-2023-49105 is known exploited. Check your ownCloud Server version, exposure condition and current remediation.

Enterprise file server undergoing version, WebDAV exposure and security-update checks

Signal Brief

  • ownCloud's CVE-specific advisory lists Server core 10.6.0 through 10.13.0 as affected by CVE-2023-49105 under the documented signing-key condition.
  • ownCloud's current guidance recommends upgrading affected Server deployments to 10.13.3 or a later supported release, or using the vendor patch where applicable.
  • CVE-2023-49105 is in CISA's Known Exploited Vulnerabilities catalog, confirming exploitation in the wild.
  • Infinite Scale and managed ownCloud.Online are not affected by this Server 10 issue according to ownCloud.

ownCloud CVE-2023-49105 is a known-exploited vulnerability affecting self-hosted ownCloud Server 10 under specific conditions. ownCloud’s CVE-specific advisory lists core versions 10.6.0 through 10.13.0 as affected. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on August 27, 2026.

The important version distinction is that ownCloud’s original CVE advisory identifies 10.13.0 as the last affected core version, while ownCloud’s broader current security guidance recommends moving Server deployments below 10.13.3 to 10.13.3 and specifically says CVE-2023-49105 can be addressed by upgrading to 10.13.3 or applying the vendor patch where applicable. Administrators should therefore follow the current vendor guidance rather than deliberately stopping at an older intermediate release.

Check whether your ownCloud Server is affected

You run ownCloud Server core 10.6.0 through 10.13.0

Your deployment falls within the CVE-specific affected range identified by ownCloud. Check the documented signing-key condition and follow ownCloud’s current remediation guidance.

You run a later ownCloud Server release

Your version is outside the original CVE-specific affected range. Confirm the version actually deployed and continue following current ownCloud security guidance for the supported Server release you operate.

You use Infinite Scale or managed ownCloud.Online

ownCloud says these products are not affected by this Server 10 vulnerability. Do not apply the ownCloud Server 10 version matrix to them.

Decision path for checking ownCloud Server versions, signing-key exposure and current remediation
The CVE-specific range is 10.6.0 through 10.13.0; current ownCloud guidance recommends 10.13.3 or a later supported release.

Which ownCloud versions are affected by CVE-2023-49105?

ownCloud’s direct advisory lists core 10.6.0 through 10.13.0 as affected by CVE-2023-49105.

The vulnerability concerns the WebDAV API and use of pre-signed URLs. According to ownCloud, exploitation requires the attacker to know the victim username and the victim user to have no signing key configured. ownCloud states that having no signing key configured is the default condition.

Why do 10.13.1 and 10.13.3 both appear in security guidance?

The two version numbers describe different parts of the remediation history.

  • 10.13.1: the original CVE-specific fix history follows from the direct advisory identifying 10.13.0 as the last affected core version.
  • 10.13.3: ownCloud’s later grouped security guidance recommends upgrading Server deployments below 10.13.3 and specifically lists upgrading to 10.13.3 or using the vendor patch as remediation for CVE-2023-49105.

For a current remediation decision, follow ownCloud’s current guidance and use 10.13.3 or a later supported Server release rather than intentionally remaining on an older intermediate version.

What can CVE-2023-49105 allow?

Under the documented conditions, ownCloud says an unauthenticated attacker can access, modify or delete files through the affected WebDAV path. That creates confidentiality and integrity risk for data held on a vulnerable self-hosted Server deployment.

What should ownCloud Server administrators do?

  1. Confirm which ownCloud product you operate: Server, Infinite Scale or managed ownCloud.Online.
  2. If you run ownCloud Server, confirm the core version actually deployed.
  3. If the server falls within the CVE-specific affected range, review whether the documented signing-key condition applies.
  4. Follow ownCloud’s current remediation guidance by moving to 10.13.3 or a later supported Server release, or use the specific vendor patch where applicable.
  5. After remediation, confirm the expected Server version is actually deployed.

Is CVE-2023-49105 actively exploited?

Yes. CVE-2023-49105 is in CISA’s Known Exploited Vulnerabilities catalog. Its addition on August 27, 2026 establishes that exploitation has been observed in the wild.

This exploitation state increases remediation urgency, but it does not prove that every vulnerable ownCloud Server was attacked or compromised.

Does the CISA remediation deadline apply to every organization?

No. CISA KEV is useful evidence that exploitation is occurring, but CISA’s binding remediation deadlines apply in the U.S. federal context. TPS does not generalize those compliance deadlines to Indian organizations or private operators.

What does patching establish?

Updating and verifying the deployed ownCloud Server version establishes that the known vulnerable software state has been remediated according to current vendor guidance.

It does not establish whether unauthorized file access, modification or deletion occurred before remediation. That historical question requires evidence from the individual environment and is outside what version data alone can prove.

Are there ownCloud-specific indicators of compromise?

TPS did not recover a complete authoritative CVE-2023-49105-specific indicator-of-compromise or forensic checklist from the reviewed primary sources.

For that reason, this article does not invent file names, log signatures or attacker artifacts. Administrators with independent evidence of suspicious file access or other security anomalies should use their established hosting or incident-response process.

Limitations & unresolved facts

  • The number of organizations currently running a vulnerable ownCloud Server version is unknown.
  • The scale and geographic breadth of exploitation are not established by the reviewed evidence.
  • TPS cannot determine whether a particular ownCloud deployment was compromised.
  • No complete authoritative CVE-specific forensic or indicator-of-compromise checklist was recovered.
  • The exact CISA KEV publication clock time was not established.

Verification method

ThePulseSignal reviewed ownCloud’s direct CVE-2023-49105 advisory, ownCloud’s broader current security guidance and the current known-exploitation state. TPS reconciled the original CVE-specific affected range separately from the vendor’s later 10.13.3 remediation recommendation.

Frequently asked questions

Which ownCloud versions are affected by CVE-2023-49105?

ownCloud’s direct CVE advisory lists core versions 10.6.0 through 10.13.0.

Should I upgrade to ownCloud 10.13.1 or 10.13.3?

For a current remediation decision, follow ownCloud’s later guidance and use 10.13.3 or a later supported Server release. The 10.13.1 reference comes from the original CVE-specific fix history.

Is ownCloud Infinite Scale affected?

ownCloud says Infinite Scale is not affected by this Server 10 issue.

Is managed ownCloud.Online affected?

ownCloud says managed ownCloud.Online is not affected by this Server 10 issue.

Is CVE-2023-49105 actively exploited?

Yes. CISA added CVE-2023-49105 to the Known Exploited Vulnerabilities catalog on August 27, 2026.

Public provenanceVerification & change history

This log separates publication, substantive reader-facing updates and source-verification checks. Older maintenance activity may predate detailed public logging.

  1. Verified

    TPS completed a source-verification pass.

  2. Published

    Article first published.

Trust boundary

Disclaimer

ThePulseSignal (TPS) provides this evidence-led informational and editorial security guidance for ownCloud administrators. TPS cannot determine whether a specific server was exploited, and no complete authoritative CVE-specific indicator-of-compromise checklist was recovered. Verify the current ownCloud security guidance and applicable official security advisories before consequential remediation or incident-response decisions.