CVE-2023-49105
ownCloud before 10.13.1: WebDAV API authentication bypass reads, writes and deletes any user's files (CISA KEV)
- Severity
- critical
- Affected product
- ownCloud
- Affected versions
- ownCloud < 10.13.1
- Fixed in
- ownCloud 10.13.1
- Added to NewScan
- 2026-08-28
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints ownCloud from its response and reports this CVE when the detected version falls inside the affected range below.
MEASURED 2026-08-28 against training/cve/vulhub owncloud/CVE-2023-49103 (vulhub/owncloud:10.12.1, cvectl slug owncloud-graphapi). The version arrives from the tech_signatures "ownCloud" version_from on /status.php, added in the same batch and MEASURED to capture 10.12.1 there; without that row this is dead data, because nothing fingerprinted ownCloud at all. CISA KEV, CVSS 9.8, EPSS 41% - the highest-ranked line in the 2026-08-28 window and an old CVE that re-entered it by being added to KEV. The bug: pre-signed WebDAV URLs are accepted with no signing key configured, so knowing a victim's username is the whole precondition for reading, changing or deleting their files with no credentials at all. VERSION-MATCH ONLY, and not a close call: an in-band confirmation would mean reading or deleting a stranger's file, which is the damage the finding warns about. NO `ge`, matching the advisory's own wording ('owncloud/core before 10.13.1') - ownCloud's own text does not name a floor and inventing one would silently un-flag old installs, which are the more likely victims. CVE-2023-49103 from the same November 2023 batch is deliberately NOT a row here: it is directly observable, so it ships as an exposure.json row that PROVES it on the response rather than inferring it from a number, and putting it in both packs would report one bug twice.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →