← Back

CVE-2025-66552

nvd nist
Published: Dec 5, 2025Modified: Jun 17, 2026

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1, incorrect path handling with groupfolders caused the admin_audit app to not properly log all actions on files and folders inside groupfolders. This vulnerability is fixed in Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1.

Affected (4)

1 product
Nextcloud Server
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Nextcloud
From 30.0.0 to 30.0.9
From 31.0.0 to 31.0.1
From 30.0.0 to 30.0.9
From 31.0.0 to 31.0.1

References (4)

Source: security-advisories@github.com
Issue Tracking
Source: security-advisories@github.com
Issue TrackingVendor Advisory

Timeline

No history available yet.