PT-2025-49265 · Nextcloud+1 · Nextcloud Server+2
Published
2025-12-05
·
Updated
2026-01-29
·
CVE-2025-66510
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Nextcloud Server versions prior to 31.0.10
Nextcloud Server version 32.0.1
Nextcloud Enterprise Server versions prior to 28.0.14.11
Nextcloud Enterprise Server versions prior to 29.0.16.8
Nextcloud Enterprise Server versions prior to 30.0.17.3
Nextcloud Enterprise Server versions prior to 31.0.10
Description
Nextcloud Server and Nextcloud Enterprise Server contain a flaw where the contacts search function does not enforce proper access controls. This allows an authenticated user to access personal data, such as emails, names, and identifiers, belonging to other users without authorization. The affected data pertains to accounts that have not been added as contacts by the user.
Recommendations
Update Nextcloud Server to version 31.0.10 or later.
Update Nextcloud Server to version 32.0.1 or later.
Update Nextcloud Enterprise Server to version 28.0.14.11 or later.
Update Nextcloud Enterprise Server to version 29.0.16.8 or later.
Update Nextcloud Enterprise Server to version 30.0.17.3 or later.
Update Nextcloud Enterprise Server to version 31.0.10 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nextcloud Enterprise Server
Nextcloud Server
Red Os