27 August 2026
Reference: CVE-2023-49105
1. What is being reported?
The vulnerability affects ownCloud versions before 10.13.1. It allows someone who knows a username to use special web links to access or modify files without logging in, but only if the user hasn’t set up a signing key to protect their files.
2. What this means in plain English
If your organisation uses ownCloud and users haven’t configured signing keys, attackers could steal or damage your files without needing a password. This could lead to data loss or exposure of sensitive information.
3. Could this affect a small business?
Small businesses or charities using ownCloud versions between 10.6.0 and before 10.13.1 could be affected, especially if signing keys are not in use. Organisations not using ownCloud or using updated versions with signing keys are likely not affected.
4. What to do now
- Check if your organisation uses ownCloud and identify the version installed.
- Confirm whether signing keys are configured for all users who store files on ownCloud.
- Apply any vendor-provided updates or mitigations immediately as per ownCloud’s instructions.
- If updates or mitigations are not available, consider discontinuing use of ownCloud until the issue is resolved.
5. Ask your IT provider
Can you confirm if our ownCloud installation is affected by CVE-2023-49105 and whether all users have signing keys configured to protect their files?
6. Bottom line
If you use ownCloud, act quickly to update or secure it to prevent unauthorised file access.
Information sourced from CISA KEV, NVD, and reputable security reports.