A notable security vulnerability has been discovered in Nextcloud Server and Nextcloud Enterprise Server, identified as CVE-2025-66510. This flaw could allow unauthorized access to sensitive user information. For anyone managing a Nextcloud instance, understanding this issue and taking the necessary steps to secure your system is crucial.
Overview
The vulnerability in Nextcloud Server and Nextcloud Enterprise Server allowed the contacts search function to improperly reveal personal data of other users. This includes sensitive details like email addresses, names, and unique identifiers. Essentially, an authenticated user could find information about accounts even if those users were not part of their contact list or otherwise connected to them.
CVE Details
Product Name: Nextcloud Server, Nextcloud Enterprise Server
Published Date: December 5, 2025
Severity: Medium
Status: Analyzed
Affected Products
The vulnerability affects several versions of Nextcloud Server and Nextcloud Enterprise Server:
- Nextcloud Server versions prior to 31.0.10 and 32.0.1
- Nextcloud Enterprise Server versions prior to 28.0.14.11, 29.0.16.8, 30.0.17.3, and 31.0.10
Current Status
This vulnerability has been analyzed and publicly disclosed. Details regarding its impact and recommended solutions are available to help users mitigate the risk.
Severity Level
CVE-2025-66510 is rated with a Medium severity. The CVSSv3 base score for this vulnerability is 4.5. While it requires an authenticated user and some user interaction, the potential for high confidentiality impact makes it a significant concern.
Possible Solutions
Nextcloud has released patches to address this vulnerability. Users are strongly advised to upgrade their installations to the patched versions as soon as possible:
- For Nextcloud Server, upgrade to version 31.0.10 or 32.0.1.
- For Nextcloud Enterprise Server, upgrade to version 28.0.14.11, 29.0.16.8, 30.0.17.3, or 31.0.10.
There are no known workarounds for this vulnerability; upgrading is the primary solution.
References
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-495w-cqv6-wr59
https://github.com/nextcloud/server/commit/e4866860cbf24a746eb8a125587262a4c8831c57
https://github.com/nextcloud/server/pull/55657


