Description

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1, incorrect path handling with groupfolders caused the admin_audit app to not properly log all actions on files and folders inside groupfolders. This vulnerability is fixed in Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1.

INFO

Published Date :

2025-12-05T16:36:39.749Z

Last Modified :

2025-12-05T18:25:06.200Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2025-66552 vulnerability.

Vendors Products
Nextcloud
  • Nextcloud
  • Nextcloud Enterprise Server
  • Nextcloud Server
  • Server

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact