Nextcloud Server Data Exposure Vulnerability (CVE-2025-66510) — Medium Severity

A notable security vulnerability has been discovered in Nextcloud Server and Nextcloud Enterprise Server, identified as CVE-2025-66510. This flaw could allow unauthorized access to sensitive user information. For anyone managing a Nextcloud instance, understanding this issue and taking the necessary steps to secure your system is crucial.

Overview

The vulnerability in Nextcloud Server and Nextcloud Enterprise Server allowed the contacts search function to improperly reveal personal data of other users. This includes sensitive details like email addresses, names, and unique identifiers. Essentially, an authenticated user could find information about accounts even if those users were not part of their contact list or otherwise connected to them.

CVE Details

Product Name: Nextcloud Server, Nextcloud Enterprise Server
Published Date: December 5, 2025
Severity: Medium
Status: Analyzed

Affected Products

The vulnerability affects several versions of Nextcloud Server and Nextcloud Enterprise Server:

  • Nextcloud Server versions prior to 31.0.10 and 32.0.1
  • Nextcloud Enterprise Server versions prior to 28.0.14.11, 29.0.16.8, 30.0.17.3, and 31.0.10

Current Status

This vulnerability has been analyzed and publicly disclosed. Details regarding its impact and recommended solutions are available to help users mitigate the risk.

Severity Level

CVE-2025-66510 is rated with a Medium severity. The CVSSv3 base score for this vulnerability is 4.5. While it requires an authenticated user and some user interaction, the potential for high confidentiality impact makes it a significant concern.

Possible Solutions

Nextcloud has released patches to address this vulnerability. Users are strongly advised to upgrade their installations to the patched versions as soon as possible:

  • For Nextcloud Server, upgrade to version 31.0.10 or 32.0.1.
  • For Nextcloud Enterprise Server, upgrade to version 28.0.14.11, 29.0.16.8, 30.0.17.3, or 31.0.10.

There are no known workarounds for this vulnerability; upgrading is the primary solution.

References

https://github.com/nextcloud/security-advisories/security/advisories/GHSA-495w-cqv6-wr59
https://github.com/nextcloud/server/commit/e4866860cbf24a746eb8a125587262a4c8831c57
https://github.com/nextcloud/server/pull/55657

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.