CVE 5.4 MEDIUM

Nextcloud Deck app allowed user with “Can share” permission to modify permissions of other non-owners_CVE-2025-66557

5.4 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

Description

Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. Prior to 1.14.6 and 1.15.2, a bug in the permission logic allowed users with "Can share" permission to modify the permissions of other recipients. This vulnerability is fixed in 1.14.6 and 1.15.2.

Basic Information

ID CVE-2025-66557
Source GitHub_M
Published Dec 5, 2025 at 17:28

Affected Product

Vendor nextcloud
Product security-advisories
Version >= 1.15.0-beta.1, < 1.15.2
Affected Versions nextcloud security-advisories >= 1.15.0-beta.1, < 1.15.2
nextcloud security-advisories < 1.14.6

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.