{
  "id": 9938973,
  "title": "152,655 Matches for ownCloud and the CVE That Matches It Exactly",
  "url": "https://urgent.news/2026/09/26/152-655-matches-for-owncloud-and-the-cve-that-matches-it-exactly",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-26T07:20:38.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/kozhevniko/152655-matches-for-owncloud-and-the-cve-that-matches-it-exactly-12ch"
  },
  "original_language": "en",
  "account": "A single CVE-2023-49105 has been identified in the ownCloud core before version 10.13.1, resulting in 152,655 matches across ZoomEye's data. The vulnerability allows for an authentication bypass, enabling unauthorized access to files. Two ZoomEye queries executed on September 24, 2026, with specified parameters, both generated the same total of 152,655 matches, indicating that the CVE-linked population aligns entirely with the product fingerprint. This overlap suggests that the vulnerability affects a substantial number of ownCloud installations. The flaw arises from validation gaps in pre-signed URLs, which can be exploited even when no signing key is configured. To mitigate the risk, it is recommended to upgrade to the latest version of ownCloud and configure signing keys for every file owner. Additionally, monitoring WebDAV access logs and auditing file integrity can help identify and address potential vulnerabilities.",
  "summary": "152,655 Matches for ownCloud and the CVE That Matches It Exactly When a product query and a CVE filter return the same number CVE-2023-49105 is an authentication bypass in ownCloud core before 10.13.1, added to CISA's Known Exploited Vulnerabilities catalog on 27 August 2026. Two ZoomEye queries ran on 24 September 2026 with sub_type=all and a page size of one. app=\"ownCloud\" returned 152,655…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}