Nextcloud Groupfolders Improper Privilege Management Vulnerability (CVE-2025-66545) — Low Severity

Understanding the Nextcloud Groupfolders Vulnerability

Nextcloud Groupfolders, a feature that allows administrators to set up shared folders for groups and teams, has a security vulnerability. This issue, identified as CVE-2025-66545, could allow a user with read-only access to restore files that have been moved to the trash bin. This essentially grants more permissions than intended, as a read-only user should not be able to manipulate files in this way.

CVE Details

Product: Nextcloud Groupfolders

Published Date: December 05, 2025

Severity: Low

Status: Analyzed

Affected Products

The vulnerability impacts several versions of Nextcloud Groupfolders. Users are advised to check their current installation against the following affected versions:

  • Nextcloud Groupfolders prior to 14.0.11
  • Nextcloud Groupfolders prior to 15.3.12
  • Nextcloud Groupfolders prior to 16.0.15
  • Nextcloud Groupfolders prior to 17.0.14
  • Nextcloud Groupfolders prior to 18.1.8
  • Nextcloud Groupfolders prior to 19.1.8
  • Nextcloud Groupfolders prior to 20.1.2

Current Status

The vulnerability has been thoroughly analyzed, and patches have been released to address the issue. It is crucial for users to update their Nextcloud Groupfolders installations to the fixed versions to ensure the security of their data.

Severity Level

This vulnerability is rated as Low Severity. While it doesn’t pose an immediate critical threat, it’s important to understand that any unauthorized privilege escalation can lead to unexpected data manipulation or system behavior. Addressing even low-severity vulnerabilities is a key practice in maintaining a robust security posture.

Possible Solutions

The good news is that Nextcloud has already provided fixes for this vulnerability. To protect your Nextcloud Groupfolders, you should update to one of the following versions or later:

  • Nextcloud Groupfolders 14.0.11
  • Nextcloud Groupfolders 15.3.12
  • Nextcloud Groupfolders 16.0.15
  • Nextcloud Groupfolders 17.0.14
  • Nextcloud Groupfolders 18.1.8
  • Nextcloud Groupfolders 19.1.8
  • Nextcloud Groupfolders 20.1.2

Always ensure your Nextcloud instance and all its components are kept up-to-date with the latest security patches to mitigate potential risks.

References

https://github.com/nextcloud/groupfolders/commit/bbe87ebed8da23e9df4db637a76fbc8d36439d58

https://github.com/nextcloud/groupfolders/issues/4041

https://github.com/nextcloud/groupfolders/pull/4076

https://github.com/nextcloud/security-advisories/security/advisories/GHSA-2vrq-fhmf-c49m

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.