← Back

CVE-2025-66557

nvd nist
Published: Dec 5, 2025Modified: Jun 17, 2026

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. Prior to 1.14.6 and 1.15.2, a bug in the permission logic allowed users with "Can share" permission to modify the permissions of other recipients. This vulnerability is fixed in 1.14.6 and 1.15.2.

Affected (2)

Products: Nextcloud: Deck
1 product
Deck
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Nextcloud
From 1.14.0 to 1.14.6
From 1.15.0 to 1.15.2

References (4)

Source: security-advisories@github.com
Issue TrackingPatch
Source: security-advisories@github.com
Issue TrackingVendor Advisory

Timeline

No history available yet.