Find notable cyber news and cases, enriched with sources, timelines, and signals.

OwnCloud WebDAV API authentication bypass (CVE-2023-49105, actively exploited)

Vulnerability
First reported
Last updated
Happening score
H score 43
1 unique sources, 1 articles

Summary

Hide ▲

CVE-2023-49105 was added to CISA's KEV catalog after active weaponization against ownCloud instances, exposing affected systems to unauthorized file access. The flaw is a WebDAV API authentication bypass that can let an attacker access, modify, or delete files when a victim username is known and signing keys are not configured. ownCloud core 10.6.0 through 10.13.0 are affected, and 10.13.1 fixes the issue.

Related Happenings

Nuclear research body in Philippines hit by network compromise

Incident
H score33 First: 28.08.2026 18:56 Last: 28.08.2026 18:56 Sources 1

How related: The scripts targeted an ownCloud instance operated by a nuclear research body, using pre-signed URLs generated with an empty signing secret, which allowed for the unauthenticated retrieval of files over WebDAV," Hunt.io said.

About this happening: A Philippine nuclear research body suffered an ownCloud intrusion that enabled unauthenticated file retrieval and exposed 176 files totaling about 372 MB. The...

N8n sandbox escape flaws (multiple vulnerabilities)

Vulnerability
H score41 First: 04.02.2026 15:00 Last: 04.02.2026 15:00 Sources 1

About this happening: Two maximum-severity sandbox-escape flaws in n8n expose self-hosted and cloud instances to complete server takeover and credential theft. An authenticated us...

OwnCloud MFA credential-theft advisory

Advisory/Mitigation
H score66 First: 07.01.2026 16:34 Last: 07.01.2026 16:34 Sources 1

About this happening: ownCloud issued an urgent MFA advisory after reports that attackers reused stolen credentials to access self-hosted file-sharing accounts without multi-factor protecti...

Timeline

  1. 28.08.2026 18:56 1 articles · 5h ago

    CISA adds CVE-2023-49105 to the KEV catalog

    Legal Policy Action Update

    CISA added CVE-2023-49105, an ownCloud WebDAV API authentication bypass affecting core versions 10.6.0 through 10.13.0 and fixed in 10.13.1, to the Known Exploited Vulnerabilities catalog after reports that a Chinese-speaking threat actor weaponized it against a Philippine nuclear research body.

    Show sources
  2. 28.08.2026 18:56 2 articles · 5h ago

    Hunt.io ties ownCloud exploit scripts to Philippine file theft

    Technical Analysis Update

    Hunt.io identified an open directory on 31.58.209[.]241 that staged custom Python scripts and offensive tools such as Sliver, Metasploit, and Mettle, and linked the activity to an ownCloud intrusion against a Philippine nuclear research body that used pre-signed URLs generated with an empty signing secret to retrieve files over WebDAV. The stolen material amounted to 176 files totaling about 372 MB and included nuclear-material records, draft strategic plans, research reactor components, historical fuel inventories, employee personal information, a 192 MB SQL dump, and credential stores.

    Show sources