ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2023-49105
(No further detail was provided by the source for this advisory - see the link below for the full notice.)
Source: PHP.net — https://www.php.net/index.php#2026-08-27-2
Published date: 20 July 2026, 9:43 am
Source: MyCERT (CyberSecurity Malaysia) — https://www.mycert.org.my/portal/details?menu=431fab9c-d24c-4a27-ba93-e92edafdefa5&id=1921af09-3caa-47df-bb9d-1afd4bcd86cf