CVE-2025-64011: Medium severity Nextcloud NextCloud Server vulnerability

Published Dec 12, 2025
·
Updated

Nextcloud Server 30.0.0 is vulnerable to an Insecure Direct Object Reference (IDOR) in the /core/preview endpoint. Any authenticated user can access previews of arbitrary files belonging to other users by manipulating the fileId parameter. This allows unauthorized disclosure of sensitive data, such as text files or images, without prior sharing permissions.

Affected Software

2 affected components
Nextcloud NextCloud Server
Nextcloud NextCloud Server=30.0.0

Event History

Dec 12, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-64011?

CVE-2025-64011 is considered a high severity vulnerability due to its potential for unauthorized data access.

2

How do I fix CVE-2025-64011?

To fix CVE-2025-64011, update Nextcloud Server to the latest version that addresses this Insecure Direct Object Reference issue.

3

Who is affected by CVE-2025-64011?

Any authenticated user of Nextcloud Server 30.0.0 is affected by CVE-2025-64011 as they can access unauthorized file previews.

4

What type of vulnerability is CVE-2025-64011?

CVE-2025-64011 is classified as an Insecure Direct Object Reference (IDOR) vulnerability.

5

What impact does CVE-2025-64011 have on users?

CVE-2025-64011 allows unauthorized users to view sensitive files from other users, leading to potential data breaches.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203