Unrated severityNVD Advisory· Published Dec 5, 2025· Updated Dec 5, 2025
Nextcloud Server users can modify tags on files that do not belong to them
CVE-2025-66547
Description
Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 31.0.1, non-privileged users can modify tags on files they should not have access to via bulk tagging. This vulnerability is fixed in 31.0.1.
Affected products
3- Range: <31.0.1
- nextcloud/security-advisoriesv5Range: < 31.0.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- github.com/nextcloud/security-advisories/security/advisories/GHSA-hq6c-r898-fgf2mitrex_refsource_CONFIRM
- github.com/nextcloud/server/commit/b44f1568f2dc97c746281d99e2342ad679e3d8a9mitrex_refsource_MISC
- github.com/nextcloud/server/issues/51247mitrex_refsource_MISC
- github.com/nextcloud/server/pull/51288mitrex_refsource_MISC
- hackerone.com/reports/3040887mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.