← Vulnerability feed

Vulnerability record · CVE-2023-49103 · published 21 November 2023

CVE-2023-49103: ownCloud graphapi phpinfo endpoint leaks environment credentials

Owncloud · Graph Api

The ownCloud graphapi app bundles a third-party GetPhpInfo.php library that exposes a URL returning full PHP environment output (phpinfo). In containerized deployments those environment variables can include the ownCloud admin password, mail server credentials and license key. Disabling the graphapi app alone does not remove the exposure, and the leak also reveals other sensitive system configuration.

7.5 CVSS 3.1 High CISA KEV since 30 Nov 2023 EPSS 78% · top 0.4% CWE-200 · Information exposure
7.5CVSS 3.1 base score
78%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party GetPhpInfo.php library that provides a URL. When this URL is accessed, it reveals the configuration details of the PHP environment (phpinfo). This information includes all the environment variables of the webserver. In containerized deployments, these environment variables may include sensitive data such as the ownCloud admin password, mail server credentials, and license key. Simply disabling the graphapi app does not eliminate the vulnerability. Additionally, phpinfo exposes various other potentially sensitive configuration details that could be exploited by an attacker to gather information about the system. Therefore, even if ownCloud is not running in a containerized environment, this vulnerability should still be a cause for concern. Note that Docker containers from before February 2023 are not vulnerable to the credential disclosure.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityIt is in CISA KEV with a near-top EPSS score and allows unauthenticated disclosure of administrative credentials.

What it is

The ownCloud graphapi app bundles a third-party GetPhpInfo.php library that exposes a URL returning full PHP environment output (phpinfo). In containerized deployments those environment variables can include the ownCloud admin password, mail server credentials and license key. Disabling the graphapi app alone does not remove the exposure, and the leak also reveals other sensitive system configuration.

Impact

An unauthenticated attacker who reaches the endpoint gains credentials and configuration data that can enable direct administrative access to ownCloud and lateral movement to connected mail or infrastructure services.

Attack surface

Reachable over the network via a URL served by the graphapi app; the CVSS vector shows no privileges or user interaction required. Any deployment exposing the affected graphapi versions is in scope, with containerized installs at highest risk.

Exploitation

Listed in CISA KEV with a 2023-12-21 remediation due date, and EPSS is 0.784 (99.6th percentile), indicating active exploitation and very high likelihood. No ransomware campaign use is recorded.

What to do

  • Upgrade ownCloud graphapi to 0.2.1 or 0.3.1 (or later) as directed by the vendor advisory.
  • If patching is not immediately possible, block external access to the GetPhpInfo.php path and the graphapi app at the web server or reverse proxy.
  • Rotate all credentials that may have been exposed through environment variables, including the ownCloud admin password, mail server credentials and license key.
  • Review container environment variable handling and move secrets out of plain environment variables where feasible.
  • Do not rely on disabling the graphapi app alone, since the vendor states this does not eliminate the vulnerability.

Detection

  • Search web and proxy logs for requests to GetPhpInfo.php or phpinfo-related paths under the graphapi app.
  • Alert on unexpected access to graphapi endpoints from external or unfamiliar source IPs.
  • Monitor for authentication attempts or logins using the ownCloud admin account from new locations after exposure.
  • Audit container environment variables and configuration for secrets that would be disclosed by phpinfo output.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-49103 to the Known Exploited Vulnerabilities catalog on 30 November 2023 as "ownCloud graphapi Information Disclosure Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 21 December 2023.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-49103 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2023-49103), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.