A recently discovered security flaw in Nextcloud Server and Nextcloud Enterprise Server could lead to gaps in your audit logs. This vulnerability, tracked as CVE-2025-66552, is important for administrators to understand as it impacts the ability to fully track file and folder actions within shared group folders.
CVE Details
This vulnerability affects:
- Product: Nextcloud Server, Nextcloud Enterprise Server
- Published: December 5, 2025
- Severity: Medium
- Status: Analyzed
Affected Products
The issue stems from incorrect path handling within the admin_audit application when dealing with group folders. This means that certain actions performed on files and folders inside these shared group folders might not have been recorded properly in the audit logs. The affected versions include:
- Nextcloud Server versions prior to 30.0.9
- Nextcloud Server versions prior to 31.0.1
- Nextcloud Enterprise Server versions prior to 30.0.9
- Nextcloud Enterprise Server versions prior to 31.0.1
Current Status
This vulnerability has been officially analyzed. Nextcloud has released updates to address the issue.
Severity Level
CVE-2025-66552 is rated as Medium severity with a CVSS score of 4.3. This rating indicates that while an attacker needs low privileges and network access, the direct impact on confidentiality and integrity is none, and the impact on availability is low. However, insufficient logging can still be problematic for compliance and incident response, as it means crucial activity might go undetected.
Possible Solutions
Nextcloud has released patches to fix this logging vulnerability. It is strongly recommended that all users and administrators update their installations as soon as possible.
- Upgrade Nextcloud Server to version 30.0.9 or later.
- Upgrade Nextcloud Server to version 31.0.1 or later.
- Upgrade Nextcloud Enterprise Server to version 30.0.9 or later.
- Upgrade Nextcloud Enterprise Server to version 31.0.1 or later.
Currently, there are no known workarounds for this specific issue, emphasizing the importance of applying the official patches.
References
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-ww9m-f8j4-jj9x
https://github.com/nextcloud/server/commit/7cc005c43c72bc384848cf8cb851895827c412f6
https://github.com/nextcloud/server/pull/50992
https://hackerone.com/reports/2890071


