CVE-2025-66552
MEDIUMDescription
Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1, incorrect path handling with groupfolders caused the admin_audit app to not properly log all actions on files and folders inside groupfolders. This vulnerability is fixed in Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1.
Is your site exposed to CVE-2025-66552?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| nextcloud | nextcloud_server |
| nextcloud | nextcloud_server |
| nextcloud | nextcloud_server |
| nextcloud | nextcloud_server |
References
Frequently Asked Questions
What is CVE-2025-66552? +
How severe is CVE-2025-66552? +
What products are affected by CVE-2025-66552? +
How do I check if I'm vulnerable to CVE-2025-66552? +
Related Vulnerabilities
: Insufficient Logging vulnerability in OpenText Secure Content Manager on Windows allows Audit Log Manipulation.This issue affects Secure Content Manager: …
The ventilator and the Service PC lack sufficient audit logging capabilities to allow for detection of malicious activity and subsequent …
phpMyFAQ versions 3.1.0 through 4.1.6 contain an authentication bypass vulnerability in AuthLdap::create(). When LDAP authentication is enabled, after a successful …
Print Assumptions does not report that a definition was produced while universe checking was disabled when that definition reaches the …
Insufficient logging in the autotyping feature in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use a …
OpenEMR is a free and open source electronic health records and medical practice management application. A logging oversight in versions …