Nextcloud Talk Poll Draft Deletion Vulnerability (CVE-2025-66556) — Low Severity

Nextcloud Talk, a popular video and audio conferencing application for Nextcloud, had a minor security flaw. This issue allowed someone with chat permissions in a conversation to delete poll drafts created by other participants, simply by knowing the draft’s numeric ID. While this might not sound like a major threat, it’s always important to address security weaknesses to keep your data safe.

CVE Details

Nextcloud Talk
Published: December 5, 2025
Severity: Low (CVSS 3.5)
Status: Analyzed

Affected Products

This vulnerability impacts Nextcloud Talk versions ranging from 20.0.0 up to, but not including, 20.1.8, and versions from 21.0.0 up to, but not including, 21.1.2. If you are using any of these versions, your Nextcloud Talk instance could be affected.

Current Status

The vulnerability, identified as CVE-2025-66556, has been thoroughly analyzed. This means the details of the flaw are understood, and solutions have been developed.

Severity Level

This vulnerability is rated as “Low” severity, with a CVSS score of 3.5 out of 10. This indicates that while the vulnerability exists, exploiting it would likely have a limited impact. Specifically, it could lead to the deletion of poll drafts, which impacts data integrity (the accuracy and consistency of data) but not confidentiality (data secrecy) or availability (access to data). User interaction is required for the exploit to occur, and low privileges are needed.

Possible Solutions

Good news! This vulnerability has been addressed and fixed by the Nextcloud team. To protect your Nextcloud Talk installation, it is strongly recommended that you upgrade to one of the patched versions:

  • Nextcloud Talk 20.1.8
  • Nextcloud Talk 21.1.2

There are no known workarounds for this vulnerability, so applying the update is the most effective way to secure your instance.

References

https://github.com/nextcloud/security-advisories/security/advisories/GHSA-pr9f-vqgg-m2jh
https://github.com/nextcloud/spreed/commit/bd68e80d1dea98d84c1d621c2c681238cf041725
https://github.com/nextcloud/spreed/pull/15532
https://hackerone.com/reports/3247386

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.