CVE-2025-66557

N

extcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. Prior to 1.14.6 and 1.15.2, a bug in the permission logic allowed users with "Can share" permission to modify the permissions of other recipients. This vulnerability is fixed in 1.14.6 and 1.15.2.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nextcloud:deck:*:*:*:*:*:*:*:*
cpe:2.3:a:nextcloud:deck:*:*:*:*:*:*:*:*

History

09 Dec 2025, 16:46

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-05 18:15

Updated : 2025-12-09 16:46


NVD link : CVE-2025-66557

Mitre link : CVE-2025-66557

CVE.ORG link : CVE-2025-66557


JSON object : View

Products Affected
CWE
CWE-284

Improper Access Control

NVD-CWE-noinfo