Critical CVE-2023-49105, CVE-2026-102489, CVE-2026-102490 — Self-hosted file sharing and helpdesk software are being attacked: an ownCloud pre-signed URL bypass lets attackers read and modify any user's files, and Zammad has a session hijack to RCE plus a root privilege escalation. Fixed versions and checks.
Published 2026-10-08 · Last updated 2026-10-08
TL;DR: ownCloud 10.6.0–10.13.0 lets an unauthenticated attacker access, change or delete any user's files if they know the username and that user has no signing key (CVSS 9.8). Zammad 6.3.0–6.5.4 has a session hijack that leads to RCE, and DEB/RPM installs up to 7.2.2 let the zammad account escalate to root. All three are on CISA's exploited list. Upgrade to ownCloud 10.13.1+ and Zammad 7.2.2+.
| CVE-2023-49105 | ownCloud core: pre-signed URLs accepted without a signing key → unauthenticated file access/modify/delete. CVSS 9.8. Fixed 10.13.1. KEV 2026-08-27 |
|---|---|
| CVE-2026-102489 | Zammad 6.3.0–6.5.4: session hijack → RCE as the zammad user (bug present but not exploitable in 7.0.0–7.1.2). KEV 2026-10-02 |
| CVE-2026-102490 | Zammad DEB/RPM packages 1.5.0–7.2.1: services run as root and execute zammad-writable files → local root. KEV 2026-10-02 |
| Fix | ownCloud ≥ 10.13.1 (or migrate to oCIS) · Zammad ≥ 7.2.2 |
ownCloud supports pre-signed URLs so links can grant access without a login. In ownCloud core 10.6.0 through 10.13.0, those URLs were accepted even when the file owner had no signing key configured, so anyone who knows a username can craft a URL that reads, modifies or deletes that user’s files over WebDAV, without authenticating. Most users never configure a signing key, so in practice that’s nearly everyone. This bug is from 2023; its addition to CISA’s list in August 2026 means unpatched servers are still being found and abused.
Nextcloud forked from ownCloud long before this code existed and is not affected by this CVE.
zammad user. The flaw also exists in 7.0.0–7.1.2 but Zammad says framework changes make it unexploitable there.zammad account could write before dropping privileges. Anyone with a foothold as zammad, say from the bug above, could become root within seconds, because the services restart automatically. Docker and source installs are not affected by this one.# ownCloud
sudo -u www-data php occ status # shows "version"
# Zammad (package install)
zammad run rails r 'puts Version.get'
dpkg -l zammad 2>/dev/null | grep ^ii # or: rpm -q zammad
apt update && apt install zammad (or yum update zammad) to reach 7.2.2+. Docker: bump the image tag and recreate.OC-Signature/OC-Credential query parameters from IPs that aren’t your users; check for files modified or deleted unexpectedly./opt/zammad), and check root’s crontab, authorized_keys and systemd units on package installs.forward_auth.Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.