Exploited in the wild ownCloud Chinese-speaking threat actor data-breach auth-bypass
ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body
CVE Tools coverage
CISA has added ownCloud vulnerability CVE-2023-49105 to its Known Exploited Vulnerabilities catalog after a Chinese-speaking threat actor used it to compromise a nuclear research facility in the Philippines. The critical flaw, affecting versions 10.6.0 through 10.13.0, allows unauthenticated file access via WebDAV pre-signed URLs when no signing key is configured, leading to the theft of approximately 372 MB of sensitive documents including strategic plans and reactor data. Federal agencies are advised to upgrade to version 10.13.1 by August 30, 2026.