Nextcloud Tables Missing Ownership Check Vulnerability (CVE-2025-66551) — Medium Severity

Understanding the Nextcloud Tables Vulnerability

A security flaw has been found in the Nextcloud Tables application. This issue could allow a malicious user to move a column from their own created table into another user’s table. This unauthorized action could lead to data integrity issues or unauthorized access to sensitive information within the Nextcloud environment.

CVE Details

Product Name: Nextcloud Tables

Published Date: December 5, 2025

Severity: Medium

Status: Analyzed

Affected Products

The Nextcloud Tables application is affected by this vulnerability. Specifically, all versions of Nextcloud Tables from 0.4.0 up to, but not including, 0.8.6, and versions from 0.9.0 up to, but not including, 0.9.3 are vulnerable.

Current Status

This vulnerability has been analyzed and confirmed by the Nextcloud security team. Fixes are available, and users are strongly advised to update their installations.

Severity Level

The vulnerability is rated as Medium severity with a CVSS score of 6.3 out of 10. While a malicious user needs some level of privilege and user interaction is required, the impact on data integrity can be high.

Possible Solutions

To protect your Nextcloud instance from this vulnerability, it is crucial to update your Nextcloud Tables application to a secure version. The recommended patched versions are:

  • Nextcloud Tables 0.8.6
  • Nextcloud Tables 0.9.3

If an immediate update is not possible, a temporary workaround is to disable the Nextcloud Tables application until you can apply the patch. It is important to plan for and apply these updates as soon as possible to maintain the security of your Nextcloud environment.

References

https://github.com/nextcloud/security-advisories/security/advisories/GHSA-w787-vwqp-8wr7

https://github.com/nextcloud/tables/commit/39f24a62fb41fd7a8bda65325f8bbafdc91c731c

https://github.com/nextcloud/tables/pull/1810

https://hackerone.com/reports/3137895

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.