PT-2025-49268 · Nextcloud+1 · Nextcloud Server+2

Published

2025-12-05

·

Updated

2026-01-29

·

CVE-2025-66547

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud Server and Enterprise Server versions prior to 31.0.1
Description Non-privileged users can modify tags on files they should not have access to through bulk tagging. This affects a self-hosted personal cloud system.
Recommendations Update to version 31.0.1 or later.

Exploit

Fix

LPE

IDOR

Weakness Enumeration

Related Identifiers

BDU:2026-03382
CVE-2025-66547
GHSA-HQ6C-R898-FGF2

Affected Products

Nextcloud Enterprise Server
Nextcloud Server
Red Os