Desert Forge IT — Arizona IT · Field-tested tools & guidesFree consult →

ownCloud CVE-2023-49105 and Zammad CVE-2026-102489/102490: Exploited Bugs in Self-Hosted Apps

Critical CVE-2023-49105, CVE-2026-102489, CVE-2026-102490 — Self-hosted file sharing and helpdesk software are being attacked: an ownCloud pre-signed URL bypass lets attackers read and modify any user's files, and Zammad has a session hijack to RCE plus a root privilege escalation. Fixed versions and checks.

Published 2026-10-08 · Last updated 2026-10-08

TL;DR: ownCloud 10.6.0–10.13.0 lets an unauthenticated attacker access, change or delete any user's files if they know the username and that user has no signing key (CVSS 9.8). Zammad 6.3.0–6.5.4 has a session hijack that leads to RCE, and DEB/RPM installs up to 7.2.2 let the zammad account escalate to root. All three are on CISA's exploited list. Upgrade to ownCloud 10.13.1+ and Zammad 7.2.2+.

CVE-2023-49105ownCloud core: pre-signed URLs accepted without a signing key → unauthenticated file access/modify/delete. CVSS 9.8. Fixed 10.13.1. KEV 2026-08-27
CVE-2026-102489Zammad 6.3.0–6.5.4: session hijack → RCE as the zammad user (bug present but not exploitable in 7.0.0–7.1.2). KEV 2026-10-02
CVE-2026-102490Zammad DEB/RPM packages 1.5.0–7.2.1: services run as root and execute zammad-writable files → local root. KEV 2026-10-02
FixownCloud ≥ 10.13.1 (or migrate to oCIS) · Zammad ≥ 7.2.2

ownCloud: CVE-2023-49105

ownCloud supports pre-signed URLs so links can grant access without a login. In ownCloud core 10.6.0 through 10.13.0, those URLs were accepted even when the file owner had no signing key configured, so anyone who knows a username can craft a URL that reads, modifies or deletes that user’s files over WebDAV, without authenticating. Most users never configure a signing key, so in practice that’s nearly everyone. This bug is from 2023; its addition to CISA’s list in August 2026 means unpatched servers are still being found and abused.

Nextcloud forked from ownCloud long before this code existed and is not affected by this CVE.

Zammad: two bugs, one chain

  • CVE-2026-102489: a session hijack in Zammad 6.3.0–6.5.4 leads to remote code execution as the zammad user. The flaw also exists in 7.0.0–7.1.2 but Zammad says framework changes make it unexploitable there.
  • CVE-2026-102490: in DEB/RPM installs (built with packager.io), Zammad’s services started as root and executed files that the zammad account could write before dropping privileges. Anyone with a foothold as zammad, say from the bug above, could become root within seconds, because the services restart automatically. Docker and source installs are not affected by this one.

Am I affected?

# ownCloud
sudo -u www-data php occ status        # shows "version"
# Zammad (package install)
zammad run rails r 'puts Version.get'
dpkg -l zammad 2>/dev/null | grep ^ii  # or: rpm -q zammad

How to patch

  • ownCloud: upgrade to 10.13.1 or later (Classic), following the ownCloud upgrade guide. ownCloud’s advisory also recommends that if you can’t upgrade immediately, you configure a signing key for users, which closes the bypass. ownCloud Infinite Scale (oCIS) is a separate codebase.
  • Zammad: apt update && apt install zammad (or yum update zammad) to reach 7.2.2+. Docker: bump the image tag and recreate.

Check for compromise

  • ownCloud: look in the web server logs for WebDAV requests carrying OC-Signature/OC-Credential query parameters from IPs that aren’t your users; check for files modified or deleted unexpectedly.
  • Zammad: review admin users and API tokens, look for unexpected files in the Zammad directory (/opt/zammad), and check root’s crontab, authorized_keys and systemd units on package installs.
  • If either was exposed on a vulnerable version, rotate passwords and API tokens for all users and the database.

Hardening for self-hosted apps

  • Put internal tools (helpdesk, file sharing used only by staff) behind a VPN or an authenticating reverse proxy such as Authelia or Authentik. See our Caddy reverse proxy guide for forward_auth.
  • Subscribe to each project’s security announcements and schedule monthly updates.

Sources

← Back to Knowledge Base

Want this handled for you?

Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.

Get a free security check →  ·  More security advisories