CVE-2025-66547

N

extcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 31.0.1, non-privileged users can modify tags on files they should not have access to via bulk tagging. This vulnerability is fixed in 31.0.1.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*

History

09 Dec 2025, 16:31

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-05 17:16

Updated : 2025-12-09 16:31


NVD link : CVE-2025-66547

Mitre link : CVE-2025-66547

CVE.ORG link : CVE-2025-66547


JSON object : View

Products Affected
CWE
CWE-639

Authorization Bypass Through User-Controlled Key