CVE-2025-66547

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 31.0.1, non-privileged users can modify tags on files they should not have access to via bulk tagging. This vulnerability is fixed in 31.0.1.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*

History

No history.

Information

Published : 2025-12-05 17:16

Updated : 2025-12-09 16:31


NVD link : CVE-2025-66547

Mitre link : CVE-2025-66547

CVE.ORG link : CVE-2025-66547


JSON object : View

Products Affected

nextcloud

  • nextcloud_server
CWE
CWE-639

Authorization Bypass Through User-Controlled Key