CVE-2025-66545: Nextcloud Groupfolders users with read-only permissions for team folder can restore deleted files from trash bin
Nextcloud Groupfolders provides admin-configured folders shared by everyone in a group or team. Prior to 14.0.11, 15.3.12, 16.0.15, 17.0.14, 18.1.8, 19.1.8, and 20.1.2, a user with read-only permission can restore a file from the trash bin. This vulnerability is fixed in 14.0.11, 15.3.12, 16.0.15, 17.0.14, 18.1.8, 19.1.8, and 20.1.2.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66545?
CVE-2025-66545 is a moderate severity vulnerability that allows users with read-only permissions to restore files from the trash bin.
How do I fix CVE-2025-66545?
To fix CVE-2025-66545, upgrade Nextcloud Groupfolders to versions 14.0.11, 15.3.12, 16.0.15, 17.0.14, 18.1.8, 19.1.8, or 20.1.2.
Which versions of Nextcloud Groupfolders are affected by CVE-2025-66545?
Versions prior to 14.0.11, 15.3.12, 16.0.15, 17.0.14, 18.1.8, 19.1.8, and 20.1.2 of Nextcloud Groupfolders are affected by CVE-2025-66545.
What impact does CVE-2025-66545 have on user permissions?
CVE-2025-66545 allows users with only read-only permissions to restore deleted files, which compromises access control.
Is there a recommended action for administrators regarding CVE-2025-66545?
Administrators should ensure that Nextcloud Groupfolders is updated to a patched version to mitigate CVE-2025-66545.