PT-2025-49296 · Nextcloud · Nextcloud

Published

2025-12-05

·

Updated

2025-12-09

·

CVE-2025-66545

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud versions prior to 14.0.11 Nextcloud versions prior to 15.3.12 Nextcloud versions prior to 16.0.15 Nextcloud versions prior to 17.0.14 Nextcloud versions prior to 18.1.8 Nextcloud versions prior to 19.1.8 Nextcloud versions prior to 20.1.2
Description Nextcloud Groupfolders allows administrators to configure folders shared with groups or teams. Prior to specific versions, a user with read-only permissions could restore files from the trash bin.
Recommendations Update to Nextcloud version 14.0.11 or later. Update to Nextcloud version 15.3.12 or later. Update to Nextcloud version 16.0.15 or later. Update to Nextcloud version 17.0.14 or later. Update to Nextcloud version 18.1.8 or later. Update to Nextcloud version 19.1.8 or later. Update to Nextcloud version 20.1.2 or later.

Exploit

Fix

Improper Neutralization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-66545
GHSA-2VRQ-FHMF-C49M

Affected Products

Nextcloud