CVE-2025-66547: Nextcloud Server users can modify tags on files that do not belong to them
Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 31.0.1, non-privileged users can modify tags on files they should not have access to via bulk tagging. This vulnerability is fixed in 31.0.1.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66547?
CVE-2025-66547 is considered a moderate severity vulnerability due to improper access controls allowing non-privileged users to modify file tags.
How do I fix CVE-2025-66547?
To fix CVE-2025-66547, upgrade Nextcloud Server or Enterprise Server to version 31.0.1 or later.
Who is affected by CVE-2025-66547?
CVE-2025-66547 affects users of Nextcloud Server and Nextcloud Enterprise Server versions prior to 31.0.1.
What are the implications of CVE-2025-66547?
The implications of CVE-2025-66547 include unauthorized modification of file tags, which can lead to data misclassification or information leakage.
What is the nature of CVE-2025-66547?
CVE-2025-66547 is an access control vulnerability that allows unauthorized users to change tags on files they shouldn't access.