CVE-2023-49105 is a critical improper authentication vulnerability in ownCloud that allows unauthenticated attackers to access, modify, or delete any file if the victim's username is known and no signing-key is configured. The vulnerability affects the WebDAV API via pre-signed URLs, enabling a complete bypass of authentication controls. This flaw poses significant risks to organizations using ownCloud for file storage and sharing. It has been flagged by CISA and is listed in their Known Exploited Vulnerabilities catalog. Remediation guidance is available through ownCloud's security advisories and CISA's BOD 26-04 directive on prioritizing security updates based on risk.