CVE 4.3 MEDIUM

Nextcloud Server admin_audit does not log all actions on files in groupfolders_CVE-2025-66552

4.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Description

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1, incorrect path handling with groupfolders caused the admin_audit app to not properly log all actions on files and folders inside groupfolders. This vulnerability is fixed in Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1.

Basic Information

ID CVE-2025-66552
Source GitHub_M
Published Dec 5, 2025 at 16:36
Modified Dec 5, 2025 at 18:25

Affected Product

Vendor nextcloud
Product security-advisories
Version >= 32.0.0beta1, < 32.0.1
Affected Versions nextcloud security-advisories >= 32.0.0beta1, < 32.0.1
nextcloud security-advisories < 31.0.9

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.