An old ownCloud vulnerability is back in the spotlight after researchers linked it to the reported theft of sensitive Philippine nuclear research data. The flaw had been fixed for nearly three years before the intrusion came to light.
CISA added CVE-2023-49105 to its Known Exploited Vulnerabilities catalog on Aug. 27, 2026, one day after Hunt.io published evidence tying the flaw to a Philippine nuclear research organization. The researchers said attacker-controlled infrastructure contained nuclear-material records, reactor-related data, personnel files, and credential material, underscoring the risk posed by unpatched internet-facing file-sharing systems.
The listing confirms that CVE-2023-49105 has been exploited in the wild. For APAC organizations, the case is especially relevant because government research bodies, utilities, and infrastructure operators often depend on long-lived internet-facing systems where delayed patching can turn an old flaw into a current breach; CISA recently flagged a previously patched Oracle WebLogic flaw under similar circumstances.
How attackers exploited the ownCloud flaw
ownCloud publicly disclosed CVE-2023-49105 on Nov. 21, 2023. Its security advisory for the vulnerability lists a CVSS score of 9.8 and says ownCloud Server versions 10.6.0 through 10.13.0 are affected.
The flaw involves pre-signed WebDAV URLs. If a user had no signing key configured — the default condition described by ownCloud — an attacker who knew the username could construct requests accepted as authenticated and access, modify, or delete files without supplying that user’s password.
The code change blocking that behavior was included in ownCloud 10.13.1 before the vulnerability was publicly disclosed. Hunt.io’s analysis of the Philippine intrusions said researchers later recovered five Python scripts implementing the technique, including tools for directory enumeration and file retrieval.
ownCloud subsequently advised affected Server customers to upgrade to 10.13.3 or obtain a specific patch as part of its broader 2023 security guidance. Organizations still running older releases should move to a currently supported version, verify signing-key configuration, and review historical WebDAV and access logs; recent attacks exploiting gaps in authentication controls show why credential protections alone may not cover every access path.
What was stolen and what remains unclear
Hunt.io said it recovered 176 files totaling about 372 MB from directories associated with the nuclear organization. The material included nuclear-material account records, research-reactor component data, radiation-safety documents, personnel records, a KeePass database, AxCrypt-encrypted files, and a BitLocker recovery key.
The total exposure remains uncertain. An attacker-created CSV referenced roughly 9 GB of material marked as exfiltrated, but most of that data was not present on the server Hunt.io examined, so the figure is not an independently verified breach total.
Simplified Chinese appeared in scripts, logs, and folder names recovered from the infrastructure. Hunt.io said the evidence pointed to a Chinese-speaking operator and assessed the activity as targeted, but it did not attribute the intrusion to the Chinese government or a named threat group.
The same server also contained evidence of a separate compromise involving a Philippine marine engineering and shipbuilding company that provides services to the Philippine Navy. The incident adds to recent APAC breaches involving sensitive organizational data, including an attack on Australia’s Origin Energy, while Hunt.io said it reported its Philippine findings to CERT-PH before publication so affected organizations could be notified.
Organizations that operated a vulnerable internet-facing ownCloud instance should review historical logs and potentially exposed credentials even after updating. Patching closes the access path; only retrospective investigation can show whether attackers used it first.
Read more: The ownCloud case is another reminder that exploitation can move faster than remediation; a recent Check Point VPN zero-day attack shows how quickly an exposed authentication flaw can become an active enterprise threat.
Let us teach you How to Talk to AI for free! Try our six-minute course at The Neuron Academy and learn a few simple ways to write better prompts and get more useful results from AI, or browse our other AI course for free for seven days. Check out all the lessons here →