OwnCloud WebDAV API authentication bypass (CVE-2023-49105, actively exploited)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2023-49105 was added to CISA's KEV catalog after active weaponization against ownCloud instances, exposing affected systems to unauthorized file access. The flaw is a WebDAV API authentication bypass that can let an attacker access, modify, or delete files when a victim username is known and signing keys are not configured. ownCloud core 10.6.0 through 10.13.0 are affected, and 10.13.1 fixes the issue.
Related Happenings
Nuclear research body in Philippines hit by network compromise
Incident
H score33
First: 28.08.2026 18:56
Last: 28.08.2026 18:56
Sources 1
How related:
The scripts targeted an ownCloud instance operated by a nuclear research body, using pre-signed URLs generated with an empty signing secret, which allowed for the unauthenticated retrieval of files over WebDAV," Hunt.io said.
About this happening:
A Philippine nuclear research body suffered an ownCloud intrusion that enabled unauthenticated file retrieval and exposed 176 files totaling about 372 MB. The...
Nuclear research body in Philippines hit by network compromise
IncidentHow related: The scripts targeted an ownCloud instance operated by a nuclear research body, using pre-signed URLs generated with an empty signing secret, which allowed for the unauthenticated retrieval of files over WebDAV," Hunt.io said.
About this happening: A Philippine nuclear research body suffered an ownCloud intrusion that enabled unauthenticated file retrieval and exposed 176 files totaling about 372 MB. The...
N8n sandbox escape flaws (multiple vulnerabilities)
Vulnerability
H score41
First: 04.02.2026 15:00
Last: 04.02.2026 15:00
Sources 1
About this happening:
Two maximum-severity sandbox-escape flaws in n8n expose self-hosted and cloud instances to complete server takeover and credential theft. An authenticated us...
N8n sandbox escape flaws (multiple vulnerabilities)
VulnerabilityAbout this happening: Two maximum-severity sandbox-escape flaws in n8n expose self-hosted and cloud instances to complete server takeover and credential theft. An authenticated us...
OwnCloud MFA credential-theft advisory
Advisory/Mitigation
H score66
First: 07.01.2026 16:34
Last: 07.01.2026 16:34
Sources 1
About this happening:
ownCloud issued an urgent MFA advisory after reports that attackers reused stolen credentials to access self-hosted file-sharing accounts without multi-factor protecti...
OwnCloud MFA credential-theft advisory
Advisory/MitigationAbout this happening: ownCloud issued an urgent MFA advisory after reports that attackers reused stolen credentials to access self-hosted file-sharing accounts without multi-factor protecti...
Timeline
-
28.08.2026 18:56 1 articles · 5h ago
CISA adds CVE-2023-49105 to the KEV catalog
Legal Policy Action UpdateCISA added CVE-2023-49105, an ownCloud WebDAV API authentication bypass affecting core versions 10.6.0 through 10.13.0 and fixed in 10.13.1, to the Known Exploited Vulnerabilities catalog after reports that a Chinese-speaking threat actor weaponized it against a Philippine nuclear research body.
Show sources
- ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body — thehackernews.com — 28.08.2026 18:56
-
28.08.2026 18:56 2 articles · 5h ago
Hunt.io ties ownCloud exploit scripts to Philippine file theft
Technical Analysis UpdateHunt.io identified an open directory on 31.58.209[.]241 that staged custom Python scripts and offensive tools such as Sliver, Metasploit, and Mettle, and linked the activity to an ownCloud intrusion against a Philippine nuclear research body that used pre-signed URLs generated with an empty signing secret to retrieve files over WebDAV. The stolen material amounted to 176 files totaling about 372 MB and included nuclear-material records, draft strategic plans, research reactor components, historical fuel inventories, employee personal information, a 192 MB SQL dump, and credential stores.
Show sources
- ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body — thehackernews.com — 28.08.2026 18:56
- ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body — thehackernews.com — 28.08.2026 18:56