Description

Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. Prior to 1.14.6 and 1.15.2, a bug in the permission logic allowed users with "Can share" permission to modify the permissions of other recipients. This vulnerability is fixed in 1.14.6 and 1.15.2.

INFO

Published Date :

2025-12-05T17:28:48.642Z

Last Modified :

2025-12-08T20:12:45.372Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2025-66557 vulnerability.

Vendors Products
Nextcloud
  • Deck

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact