ownCloud CVE-2023-49105 Exploitation Against Philippine Nuclear Research Institute
First seen Aug 30, 2026 · Updated Aug 30, 2026 · CVSS 9.8
A critical pre-authentication vulnerability in ownCloud (CVE-2023-49105, CVSS 9.8) was actively exploited by a suspected Chinese-speaking threat actor to breach a nuclear research institute in the Philippines and exfiltrate sensitive records. CISA has added the flaw to its Known Exploited Vulnerabilities catalog, confirming active in-the-wild exploitation and prompting mandated remediation for federal agencies.
Technical Analysis
CVE-2023-49105 is an authentication bypass in ownCloud's WebDAV API stemming from improper validation of pre-signed URLs, allowing attackers to access, modify, or delete files without valid credentials when certain app configurations (graphapi) are enabled. Exploitation requires no authentication and can be combined with disclosed environment variables (via a related flaw, CVE-2023-49103) to harvest admin credentials, mail server credentials, and license keys. In this campaign, the threat actor leveraged the flaw to gain unauthorized access to file storage and exfiltrate nuclear research records, indicating targeted espionage rather than opportunistic exploitation. Organizations using ownCloud instances for internal document sharing—including those integrated into RAG pipelines or used as a knowledge/document store for AI agents—should treat any connected credentials or API tokens as compromised if the affected version was internet-facing, since exposed secrets could enable downstream agent tool misuse or unauthorized data retrieval.
Affected Systems
ownCloud core versions with the graphapi app enabled (affects ownCloud versions prior to patched releases addressing CVE-2023-49105); self-hosted ownCloud instances exposed to the internet, particularly those used for file sharing in government, research, and critical infrastructure environments.
Indicators of Compromise
- No specific file hashes, IPs, or domains disclosed in source reporting; indicators pending further disclosure from CISA/Philippine CERT advisories.
Remediation Steps
- 1
Patch ownCloud Immediately
Upgrade to the latest patched version of ownCloud that remediates CVE-2023-49105 and related CVE-2023-49103.
- 2
Disable or Restrict graphapi App
If patching is not immediately possible, disable the graphapi app or restrict WebDAV API access via network controls.
- 3
Rotate Credentials and Secrets
Rotate all admin passwords, mail server credentials, and license keys potentially exposed via environment variable disclosure.
- 4
Audit Exposed Instances
Identify all internet-facing ownCloud deployments and verify against CISA KEV catalog for exploitation indicators.
- 5
Monitor for Unauthorized Access
Review WebDAV access logs for anomalous pre-signed URL usage or unauthorized file access/exfiltration patterns.
- 6
Apply CISA BOD 22-01 Timelines
Federal agencies and critical infrastructure operators should remediate per CISA's mandated KEV catalog deadlines.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.