CVE-2025-66547

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 31.0.1, non-privileged users can modify tags on files they should not have access to via bulk tagging. This vulnerability is fixed in 31.0.1.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*

History

09 Dec 2025, 16:31

Type Values Removed Values Added
First Time Nextcloud
Nextcloud nextcloud Server
References () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-hq6c-r898-fgf2 - () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-hq6c-r898-fgf2 - Patch, Vendor Advisory
References () https://github.com/nextcloud/server/commit/b44f1568f2dc97c746281d99e2342ad679e3d8a9 - () https://github.com/nextcloud/server/commit/b44f1568f2dc97c746281d99e2342ad679e3d8a9 - Patch
References () https://github.com/nextcloud/server/issues/51247 - () https://github.com/nextcloud/server/issues/51247 - Issue Tracking
References () https://github.com/nextcloud/server/pull/51288 - () https://github.com/nextcloud/server/pull/51288 - Issue Tracking
References () https://hackerone.com/reports/3040887 - () https://hackerone.com/reports/3040887 - Permissions Required, Vendor Advisory
CPE cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*

05 Dec 2025, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-05 17:16

Updated : 2025-12-09 16:31


NVD link : CVE-2025-66547

Mitre link : CVE-2025-66547

CVE.ORG link : CVE-2025-66547


JSON object : View

Products Affected

nextcloud

  • nextcloud_server
CWE
CWE-639

Authorization Bypass Through User-Controlled Key