criticalAPT

ownCloud CVE-2023-49105 Exploitation Against Philippine Nuclear Research Institute

First seen Aug 30, 2026 · Updated Aug 30, 2026 · CVSS 9.8

ownCloudCISA-KEVCVE-2023-49105pre-authenticationwebdavchina-nexuscritical-infrastructurenuclear-sectordata-theft

A critical pre-authentication vulnerability in ownCloud (CVE-2023-49105, CVSS 9.8) was actively exploited by a suspected Chinese-speaking threat actor to breach a nuclear research institute in the Philippines and exfiltrate sensitive records. CISA has added the flaw to its Known Exploited Vulnerabilities catalog, confirming active in-the-wild exploitation and prompting mandated remediation for federal agencies.

Technical Analysis

CVE-2023-49105 is an authentication bypass in ownCloud's WebDAV API stemming from improper validation of pre-signed URLs, allowing attackers to access, modify, or delete files without valid credentials when certain app configurations (graphapi) are enabled. Exploitation requires no authentication and can be combined with disclosed environment variables (via a related flaw, CVE-2023-49103) to harvest admin credentials, mail server credentials, and license keys. In this campaign, the threat actor leveraged the flaw to gain unauthorized access to file storage and exfiltrate nuclear research records, indicating targeted espionage rather than opportunistic exploitation. Organizations using ownCloud instances for internal document sharing—including those integrated into RAG pipelines or used as a knowledge/document store for AI agents—should treat any connected credentials or API tokens as compromised if the affected version was internet-facing, since exposed secrets could enable downstream agent tool misuse or unauthorized data retrieval.

Affected Systems

ownCloud core versions with the graphapi app enabled (affects ownCloud versions prior to patched releases addressing CVE-2023-49105); self-hosted ownCloud instances exposed to the internet, particularly those used for file sharing in government, research, and critical infrastructure environments.

Indicators of Compromise

  • No specific file hashes, IPs, or domains disclosed in source reporting; indicators pending further disclosure from CISA/Philippine CERT advisories.

Remediation Steps

  1. 1

    Patch ownCloud Immediately

    Upgrade to the latest patched version of ownCloud that remediates CVE-2023-49105 and related CVE-2023-49103.

  2. 2

    Disable or Restrict graphapi App

    If patching is not immediately possible, disable the graphapi app or restrict WebDAV API access via network controls.

  3. 3

    Rotate Credentials and Secrets

    Rotate all admin passwords, mail server credentials, and license keys potentially exposed via environment variable disclosure.

  4. 4

    Audit Exposed Instances

    Identify all internet-facing ownCloud deployments and verify against CISA KEV catalog for exploitation indicators.

  5. 5

    Monitor for Unauthorized Access

    Review WebDAV access logs for anomalous pre-signed URL usage or unauthorized file access/exfiltration patterns.

  6. 6

    Apply CISA BOD 22-01 Timelines

    Federal agencies and critical infrastructure operators should remediate per CISA's mandated KEV catalog deadlines.

CVE / Advisory IDs

CVE-2023-49105CVE-2023-49103

Industries Most Exposed

energy/nuclear researchgovernmentcritical infrastructureresearch institutions

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.