High severity8.1NVD Advisory· Published Oct 25, 2021· Updated Jun 17, 2026
CVE-2021-39225
CVE-2021-39225
Description
Nextcloud is an open-source, self-hosted productivity platform. A missing permission check in Nextcloud Deck before 1.2.9, 1.4.5 and 1.5.3 allows another authenticated users to access Deck cards of another user. It is recommended that the Nextcloud Deck App is upgraded to 1.2.9, 1.4.5 or 1.5.3. There are no known workarounds aside from upgrading.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- nextcloud/security-advisoriesv5Range: < 1.2.9
Patches
Vulnerability mechanics
References
3- github.com/nextcloud/deck/pull/3316nvdPatchThird Party Advisory
- github.com/nextcloud/security-advisories/security/advisories/GHSA-2x96-38qg-3m72nvdThird Party Advisory
- hackerone.com/reports/1331728nvdPermissions RequiredThird Party Advisory
News mentions
0No linked articles in our index yet.