Understanding the Nextcloud Deck Permission Issue
Nextcloud Deck, a popular Kanban-style tool for personal and team project organization within Nextcloud, had a security flaw. This issue could allow certain users to change the access rights of others, even when they shouldn’t have that power. This is a significant concern for teams relying on strict access controls for their project boards.
CVE Details
- Product: Nextcloud Deck
- Published Date: December 5, 2025
- Severity: Medium
- Status: Analyzed
Affected Products
The vulnerability impacts Nextcloud Deck versions prior to 1.14.6 and 1.15.2.
Current Status
This vulnerability has been analyzed and confirmed.
Severity Level
The vulnerability has been rated with a Medium severity level. While not the most critical, it’s important to address promptly as it could lead to unauthorized changes in project permissions, potentially disrupting team workflows and data integrity.
Possible Solutions
Nextcloud has released updates that fix this permission logic issue. Users should update their Nextcloud Deck installations to the following versions or later:
- Nextcloud Deck 1.14.6
- Nextcloud Deck 1.15.2
Applying these patches is crucial to ensure that user permissions are enforced correctly and to prevent unauthorized modifications by users with “Can share” privileges.
References
https://github.com/nextcloud/deck/commit/f1da8b30a455f02373d44154da04494c949a95ae
https://github.com/nextcloud/deck/pull/7131
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-wwr8-hx9g-rjvv
https://hackerone.com/reports/3247499


