CVE-2025-66552

Source
https://cve.org/CVERecord?id=CVE-2025-66552
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-66552.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-66552
Aliases
Published
2025-12-05T16:36:39.749Z
Modified
2026-08-12T03:51:45.526408996Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
Nextcloud Server admin_audit does not log all actions on files in groupfolders
Details

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1, incorrect path handling with groupfolders caused the admin_audit app to not properly log all actions on files and folders inside groupfolders. This vulnerability is fixed in Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66552.json",
    "cwe_ids": [
        "CWE-778"
    ],
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/nextcloud/server

Affected ranges

Type
GIT
Repo
https://github.com/nextcloud/server
Events
Database specific
Show details
{
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ],
    "cpe": [
        "cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*",
        "cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "30.0.0"
        },
        {
            "fixed": "30.0.9"
        },
        {
            "introduced": "31.0.0"
        },
        {
            "fixed": "31.0.1"
        }
    ]
}

Affected versions

v30.*
v30.0.0
v30.0.1
v30.0.1rc1
v30.0.1rc2
v30.0.2
v30.0.2rc1
v30.0.2rc2
v30.0.3
v30.0.3rc1
v30.0.3rc2
v30.0.4
v30.0.4rc1
v30.0.5
v30.0.5rc1
v30.0.6
v30.0.6rc1
v30.0.6rc2
v30.0.7
v30.0.7rc1
v30.0.7rc2
v30.0.8
v30.0.8rc1
v30.0.9rc1
v30.0.9rc2
v31.*
v31.0.0
v31.0.1rc1
v31.0.1rc2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-66552.json"