CISA KEV Alert 8/27/2026, 8:50:58 PM

CISA Adds CVE-2023-49105 to Known Exploited Vulnerabilities Catalogue

CyberSIXT Evidence Panel Source marked as original reporting
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Available

CISA has added CVE‑2023‑49105 to its Known Exploited Vulnerabilities catalogue, affecting the ownCloud file‑sharing platform. The vulnerability is an improper authentication flaw that lets an attacker access, modify or delete any file without authentication when the victim’s username is known and no signing‑key is configured.

The flaw resides in the WebDAV API handling of pre‑signed URLs, allowing unauthenticated manipulation of files via crafted requests. It carries a CVSS v3.1 base score of 9.8, rating it as critical, and a security patch is available from ownCloud. The attack vector is network‑based, requiring no user interaction or privileges beyond knowledge of a target username.

Active exploitation has been observed, which is why the entry appears in the KEV catalogue; there is currently no public confirmation of ransomware use. CISA has set a remediation deadline of 30 August 2026 for federal civilian executive branch agencies to address the vulnerability.

CISA’s required action is: “Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26‑04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s ‘Forensics Triage Requirements’ (see URL in Notes). Follow applicable BOD 26‑04 guidance for cloud services or discontinue use of the product if mitigations are unavailable.

Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26‑04 patching guidelines.” While this directive binds FCEB agencies, all organisations should review their ownCloud instances for exposure and apply the patch or mitigations promptly.

For full details, consult the NVD entry at https://nvd.nist.gov/vuln/detail/CVE-2023-49105 and the CISA KEV catalogue.

View CISA KEV Entry

Article by CyberSIXT