Nextcloud Deck Permission Logic Vulnerability (CVE-2025-66557) — Medium Severity

Understanding the Nextcloud Deck Permission Issue

Nextcloud Deck, a popular Kanban-style tool for personal and team project organization within Nextcloud, had a security flaw. This issue could allow certain users to change the access rights of others, even when they shouldn’t have that power. This is a significant concern for teams relying on strict access controls for their project boards.

CVE Details

  • Product: Nextcloud Deck
  • Published Date: December 5, 2025
  • Severity: Medium
  • Status: Analyzed

Affected Products

The vulnerability impacts Nextcloud Deck versions prior to 1.14.6 and 1.15.2.

Current Status

This vulnerability has been analyzed and confirmed.

Severity Level

The vulnerability has been rated with a Medium severity level. While not the most critical, it’s important to address promptly as it could lead to unauthorized changes in project permissions, potentially disrupting team workflows and data integrity.

Possible Solutions

Nextcloud has released updates that fix this permission logic issue. Users should update their Nextcloud Deck installations to the following versions or later:

  • Nextcloud Deck 1.14.6
  • Nextcloud Deck 1.15.2

Applying these patches is crucial to ensure that user permissions are enforced correctly and to prevent unauthorized modifications by users with “Can share” privileges.

References

https://github.com/nextcloud/deck/commit/f1da8b30a455f02373d44154da04494c949a95ae

https://github.com/nextcloud/deck/pull/7131

https://github.com/nextcloud/security-advisories/security/advisories/GHSA-wwr8-hx9g-rjvv

https://hackerone.com/reports/3247499

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.