CVE-2023-49105: ownCloud Auth Bypass Hits Nuclear Research Facility

CISA added ownCloud CVE-2023-49105 (CVSS 9.8) to KEV after a Chinese-speaking actor used the WebDAV auth bypass to exfiltrate nuclear records from a Philippine research body.

2026-08-31T22:34:10.107Z
Rudra Verma, Senior Security Architect & Researcher