CVE-2025-66513: Nextcloud Tables app share information not limited to relevant users
Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.9, 0.9.6, and 1.0.1, the information which table (numeric ID) is shared with which groups or users and the respective permissions was not limited to privileged users. This vulnerability is fixed in 0.8.9, 0.9.6, and 1.0.1.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66513?
CVE-2025-66513 is considered a high severity vulnerability due to the improper access control for table sharing permissions.
How do I fix CVE-2025-66513?
To fix CVE-2025-66513, upgrade Nextcloud Tables to version 0.8.9, 0.9.6, or 1.0.1 or later.
What systems are affected by CVE-2025-66513?
CVE-2025-66513 affects Nextcloud Tables versions prior to 0.8.9, 0.9.6, and 1.0.1.
What are the consequences of CVE-2025-66513 if not addressed?
If CVE-2025-66513 is not addressed, unauthorized users may gain access to sensitive data through improper permissions.
What specific functionality does CVE-2025-66513 affect in Nextcloud Tables?
CVE-2025-66513 affects the sharing of table numeric IDs and permissions with users or groups, leading to potential data exposure.