CVE-2025-66513

Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.9, 0.9.6, and 1.0.1, the information which table (numeric ID) is shared with which groups or users and the respective permissions was not limited to privileged users. This vulnerability is fixed in 0.8.9, 0.9.6, and 1.0.1.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nextcloud:tables:*:*:*:*:*:nextcloud:*:*
cpe:2.3:a:nextcloud:tables:*:*:*:*:*:nextcloud:*:*
cpe:2.3:a:nextcloud:tables:*:*:*:*:*:nextcloud:*:*

History

No history.

Information

Published : 2025-12-05 18:15

Updated : 2025-12-09 19:32


NVD link : CVE-2025-66513

Mitre link : CVE-2025-66513

CVE.ORG link : CVE-2025-66513


JSON object : View

Products Affected

nextcloud

  • tables
CWE
CWE-639

Authorization Bypass Through User-Controlled Key