Zero Day Room
Live
Vulnerabilities

CISA: ownCloud vulnerability exploited

CISA adds critical ownCloud flaw CVE 2023-49105 to its exploited catalog after a Chinese-speaking threat actor used it to steal nuclear research files from

CISA adds critical ownCloud flaw CVE 2023-49105 to its exploited catalog after a Chinese-speaking threat actor used it to...

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a critical ownCloud vulnerability to its Known Exploited Vulnerabilities catalog on Thursday. The flaw, tracked as CVE-2023-49105, was used to steal nuclear records from a research body in the Philippines.

According to threat intelligence firm Hunt.io, a Chinese-speaking threat actor staged custom Python scripts on an open directory at host "31.58.209[.]241". These scripts exploited the ownCloud vulnerability to target a Philippine nuclear research body and a marine engineering company serving the Navy.

Critical ownCloud authentication bypass

The vulnerability is a WebDAV API authentication bypass with a CVSS score of 9.8. It impacts ownCloud "core"versions from 10.6.0 through 10.13.0. ownCloud fixed the issue in version 10.13.1 in November 2023."An attacker with knowledge of valid usernames on the instance could construct signed WebDAV requests that would be accepted by the server as an authentication action by that user, without ever supplying credentials,"the firm said. This works if the victim has no signing-key configured, which is the default."pcalua.exe" to invoke "mshta.exe"and download a VBScript dropper. Hunt.io attributed the attacks to a Chinese speaker."The operator, whether state-affiliated, contracted, or working independently, conducted a deliberate intrusion against Philippine nuclear and defense-adjacent organizations,"Hunt.io stated. The firm noted the marine company's ties to the Navy align with interests related to South China Sea tensions."These activities were not part of, and did not contribute to, the chain of events that led to the Hugging Face compromise," OpenAI said. Federal agencies must patch the Linux Kernel flaw by August 30, 2026, and the Artifactory bug by September 10, 2026.

Related coverage

More from Vulnerabilities