CVE-2023-49103Active Exploitation(owncloud / graph_api)

LOWCVSS 7.5 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for owncloud graph_api systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party GetPhpInfo.php library that provides a URL. When this URL is accessed, it reveals the configuration details of the PHP environment (phpinfo). This information includes all the environment variables of the webserver. In containerized deployments, these environment variables may include sensitive data such as the ownCloud admin password, mail server credentials, and license key. Simply disabling the graphapi app does not eliminate the vulnerability. Additionally, phpinfo exposes various other potentially sensitive configuration details that could be exploited by an attacker to gather information about the system. Therefore, even if ownCloud is not running in a containerized environment, this vulnerability should still be a cause for concern. Note that Docker containers from before February 2023 are not vulnerable to the credential disclosure.

3.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-12-21. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • graph_api

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-07-10); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
graph_api

2 versions affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-10: 1Mentions · 2026-08-28: 1Active Exploitation · 2026-07-10: 1Technical Details · 2026-08-28: 107-1008-28
Signal classification2 categories
Active Exploitation
150.0%
General
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-07-101
Active Exploitation1
2026-08-281
General1
Full discourse2 posts
  • NewNormal Security@NewScanTeam
    General

    NewNormal Security turns the last 24 hours of CVEs into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 28 Aug 2026 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 🚨 Outdated ownCloud — WebDAV answers with no login, so a known username is enough to read or delete their files, or a leftover test file prints the admin password, as seen in ownCloud CVE-2023-49105, CVE-2023-49103 ⚡ Outdated Budibase — an uploaded plugin runs as code, and low-privilege users reach data and roles their app denies them, as seen in Budibase CVE-2026-82244, CVE-2026-82239, CVE-2026-82240, CVE-2026-82241, CVE-2026-82242, CVE-2026-82243, CVE-2026-82245, CVE-2026-82246 📦 FileBrowser with no maintainer left — a named pipe in a shared folder hangs downloads, and no fix will ever ship, as seen in FileBrowser CVE-2026-82235, CVE-2026-82237, CVE-2026-82238 Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #AuthBypass #CSO #REDTEAM

    Post summary

    The Daily CVE report enumerates several outdated applications, details their vulnerability mechanics, and highlights potential exploitation paths, but does not provide exploits, patches, or evidence of active attacks.

    0000071
    6 followersView on X
  • Loginsoft Threat Intel@Loginsoft_Intel
    Active Exploitation

    Cytellite recent detection targeting CVE-2023-49103 — 1337 Services GmbH Visit -- https://cti.loginsoft.com/ip/124.198.131.172 #Loginsoft #Cytellite #Cybersecurity #CVE202349103 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/VfFN39j1Dy

    Post summary

    The tweet indicates that CVE‑2023‑49103 is being actively targeted by threat actors, as reported by Cytellite, but no PoC, exploit tool, patch, or detailed technical information is provided.

    0000052
    22 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appowncloudgraph_api0.2.0--
Appowncloudgraph_api0.3.0--

Explore more