← All CVEs NewScan detects
critical

CVE-2023-49105

ownCloud before 10.13.1: WebDAV API authentication bypass reads, writes and deletes any user's files (CISA KEV)

Severity
critical
Affected product
ownCloud
Affected versions
ownCloud < 10.13.1
Fixed in
ownCloud 10.13.1
Added to NewScan
2026-08-28
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints ownCloud from its response and reports this CVE when the detected version falls inside the affected range below.

MEASURED 2026-08-28 against training/cve/vulhub owncloud/CVE-2023-49103 (vulhub/owncloud:10.12.1, cvectl slug owncloud-graphapi). The version arrives from the tech_signatures "ownCloud" version_from on /status.php, added in the same batch and MEASURED to capture 10.12.1 there; without that row this is dead data, because nothing fingerprinted ownCloud at all. CISA KEV, CVSS 9.8, EPSS 41% - the highest-ranked line in the 2026-08-28 window and an old CVE that re-entered it by being added to KEV. The bug: pre-signed WebDAV URLs are accepted with no signing key configured, so knowing a victim's username is the whole precondition for reading, changing or deleting their files with no credentials at all. VERSION-MATCH ONLY, and not a close call: an in-band confirmation would mean reading or deleting a stranger's file, which is the damage the finding warns about. NO `ge`, matching the advisory's own wording ('owncloud/core before 10.13.1') - ownCloud's own text does not name a floor and inventing one would silently un-flag old installs, which are the more likely victims. CVE-2023-49103 from the same November 2023 batch is deliberately NOT a row here: it is directly observable, so it ships as an exposure.json row that PROVES it on the response rather than inferring it from a number, and putting it in both packs would report one bug twice.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →