{"id":"CVE-2025-66552","summary":"Nextcloud Server admin_audit does not log all actions on files in groupfolders","details":"Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1, incorrect path handling with groupfolders caused the admin_audit app to not properly log all actions on files and folders inside groupfolders. This vulnerability is fixed in Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1.","aliases":["BIT-nextcloud-2025-66552","GHSA-ww9m-f8j4-jj9x"],"modified":"2026-08-12T03:51:45.526408996Z","published":"2025-12-05T16:36:39.749Z","database_specific":{"cwe_ids":["CWE-778"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66552.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://hackerone.com/reports/2890071"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66552.json"},{"type":"ADVISORY","url":"https://github.com/nextcloud/security-advisories/security/advisories/GHSA-ww9m-f8j4-jj9x"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66552"},{"type":"FIX","url":"https://github.com/nextcloud/server/commit/7cc005c43c72bc384848cf8cb851895827c412f6"},{"type":"FIX","url":"https://github.com/nextcloud/server/pull/50992"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nextcloud/server","events":[{"introduced":"656488893e2175e19fbe273d76a5e16a598000c7"},{"fixed":"8c428e22e4823b3df1870264fb7169ffd154118e"},{"introduced":"051e46a7a272300cf7c90b3e330fd1501fd6a996"},{"fixed":"ca86133382c6efb7c0eb82e5b9806a84bad2b9dc"},{"fixed":"7cc005c43c72bc384848cf8cb851895827c412f6"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":["cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*","cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*"],"extracted_events":[{"introduced":"30.0.0"},{"fixed":"30.0.9"},{"introduced":"31.0.0"},{"fixed":"31.0.1"}]}}],"versions":["v30.0.9rc2","v30.0.9rc1","v30.0.8rc1","v30.0.8","v30.0.7","v30.0.7rc2","v31.0.1rc2","v30.0.7rc1","v31.0.1rc1","v31.0.0","v30.0.6","v30.0.6rc2","v30.0.6rc1","v30.0.5","v30.0.5rc1","v30.0.4","v30.0.4rc1","v30.0.3","v30.0.3rc2","v30.0.3rc1","v30.0.2","v30.0.2rc2","v30.0.2rc1","v30.0.1","v30.0.1rc2","v30.0.1rc1","v30.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-66552.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"}]}