CVE-2025-66557

Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. Prior to 1.14.6 and 1.15.2, a bug in the permission logic allowed users with "Can share" permission to modify the permissions of other recipients. This vulnerability is fixed in 1.14.6 and 1.15.2.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nextcloud:deck:*:*:*:*:*:*:*:*
cpe:2.3:a:nextcloud:deck:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-05 18:15

Updated : 2025-12-09 16:46


NVD link : CVE-2025-66557

Mitre link : CVE-2025-66557

CVE.ORG link : CVE-2025-66557


JSON object : View

Products Affected

nextcloud

  • deck
CWE
CWE-284

Improper Access Control

NVD-CWE-noinfo