CVE-2025-66551: Nextcloud Tables is missing an ownership check which allows moving columns into tables of other users
Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.6 and 0.9.3, a malicious user was able to create their own table and then move a column to a victims table. This vulnerability is fixed in 0.8.6 and 0.9.3.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66551?
CVE-2025-66551 is considered to have a medium severity rating due to the potential for unauthorized manipulation of tables by malicious users.
How do I fix CVE-2025-66551?
To fix CVE-2025-66551, upgrade Nextcloud Tables to version 0.8.6 or 0.9.3 or later.
What versions of Nextcloud Tables are affected by CVE-2025-66551?
CVE-2025-66551 affects Nextcloud Tables versions prior to 0.8.6 and 0.9.3.
What type of attack is possible due to CVE-2025-66551?
Due to CVE-2025-66551, a malicious user could create their own table and move a column into a victim's table.
Is there a known exploit for CVE-2025-66551?
There are no specific known exploits publicly disclosed for CVE-2025-66551, but the vulnerability allows for table manipulation which poses security risks.