Skip to content

Products › Brands

Brand

ownCloud: actively exploited vulnerabilities

2 vulnerabilities in ownCloud products (ownCloud Server) are in CISA’s catalog of exploited vulnerabilities, 1 of them added in the last 90 days. Last added: August 27, 2026.

By category

Add just one ownCloud category to your radar, or open its page.

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

Affected products

  • ownCloud Server2 vulnerabilities, File transfer (MFT)

Name used by CISA: ownCloud. Product families: indicative classification by this site.

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this ownCloud list.

  1. Rank 1

    ownCloud ServerCVE-2023-49105

    ownCloud Improper Authentication Vulnerability

    Hunt for compromise (CISA)CVE from 2023, added in 2026

    CVSS severity 9.8critical

    Added Aug 27, 2026

  2. Rank 2

    ownCloud ServerCVE-2023-49103

    ownCloud graphapi Information Disclosure Vulnerability

    CVSS severity 7.5high

    Added Nov 30, 2023

Follow and verify

Indicative classification, based on the vendor and product names given by CISA. How products are classified.