ownCloud Flaw Exploited to Steal Nuclear Records From P
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting ownCloud to its Known Exploited Vulnerabilities (KEV) catalog following reports th
What Happened
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2023-49105 to its Known Exploited Vulnerabilities (KEV) catalog on Thursday, following confirmed reports that the critical ownCloud flaw was used to exfiltrate nuclear-related records from a Philippine research organization. The breach, which targeted the country’s nuclear research body, marks the first publicly documented case where this specific vulnerability was leveraged to steal sensitive national security data.
The attack underscores a worrying trend: CVE-2023-49105, a file takeover vulnerability in ownCloud’s WebDAV API, has now moved from theoretical risk to confirmed operational weaponization. CISA’s KEV designation obligates federal civilian agencies to patch within specified timelines, but the Philippine incident demonstrates that threat actors are already exploiting this bug in the wild beyond U.S. government networks.
Why It Matters
This is not a routine vulnerability disclosure. ownCloud is an open-source file sharing and synchronization platform widely deployed across government, research, and enterprise environments globally. The fact that a nuclear research agency was successfully compromised means threat actors have an interest in exfiltrating highly sensitive scientific and defense-related data through commonly used collaboration tools.
For organizations running ownCloud, the stakes are asymmetric: the vendor disclosed this flaw in late November 2023, yet exploitation continued into 2025. This gap between patch availability and attacker adoption highlights a persistent operational weakness in vulnerability management. Security teams should treat any unpatched ownCloud instance as an urgent compromise risk, particularly in sectors handling regulated or classified data.
Technical Details
CVE-2023-49105 stems from improper access control in ownCloud’s WebDAV endpoint. An unauthenticated attacker can construct a specially crafted HTTP request to access, modify, or delete files within a user’s account without valid credentials. The vulnerability affects ownCloud versions prior to 10.13.1, where the fix was included in the releases of 10.11.0 and 10.10.0 for some distributions.
Attack vectors observed in the Philippine incident involved direct exploitation of exposed WebDAV interfaces, likely targeting instances reachable from the internet. Indicators of compromise include unusual GET or PUT requests to /remote.php/dav/files/ paths, failed authentication logs followed by successful anonymous file access, and unauthorized bulk file downloads exhibiting patterns consistent with data staging.
Organizations should check their ownCloud logs for WebDAV traffic originating from unexpected IP addresses or containing malformed authentication tokens. The exploit requires no user interaction, making detection dependent on network and filesystem monitoring rather than endpoint alerts.
Immediate Risk
The immediate risk is elevated for any organization with an internet-exposed ownCloud deployment running an unpatched version. Given CISA’s KEV listing, exploitation is now considered highly probable in the coming weeks as more attackers adopt the technique. The Philippine attack demonstrates that even organizations outside the primary developer community’s focus are viable targets.
If your organization runs ownCloud versions below 10.13.1, assume compromise until proven otherwise and conduct a forensic review of WebDAV access logs. For those unable to patch immediately, restrict network access to ownCloud instances and enforce multi-factor authentication at the proxy layer as a compensating control. Prioritize patching over temporary mitigations where possible, as the exploit is trivial to execute and widely documented.
Security Insight
The Philippine research body compromise exposes a critical blind spot in vulnerability prioritization: the assumption that open-source collaboration tools in non-enterprise sectors are low-value targets. Nuclear research institutions, energy regulators, and government-affiliated labs store data that fuels geopolitical competition. Attackers don’t need zero-days when they can weaponize a known flaw and target sectors with slower patch cycles.
The more durable takeaway is that CISA’s KEV catalog operates as a lagging indicator. By the time a CVE earns that designation, adversaries have typically already scaled exploitation. Organizations should not wait for KEV entries but instead proactively map their ownCloud assets, identify internet-facing WebDAV endpoints, and treat any missing patch as an immediate incident response trigger. For high-value sectors, consider air-gapping classified or sensitive research data away from internet-reachable file sharing platforms entirely. The nuclear records breach will not be the last of its kind if this lesson goes unheeded.
Further Reading
Never miss a security update
Get real-time security alerts delivered to your preferred platform.
Related News
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea. The vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnera
North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign. [...]
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catal