CVE-2025-66552: Nextcloud Server admin_audit does not log all actions on files in groupfolders
Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1, incorrect path handling with groupfolders caused the adminaudit app to not properly log all actions on files and folders inside groupfolders. This vulnerability is fixed in Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66552?
CVE-2025-66552 is considered to have a moderate severity due to the improper logging of actions within group folders.
How do I fix CVE-2025-66552?
To resolve CVE-2025-66552, upgrade Nextcloud Server or Nextcloud Enterprise Server to version 30.0.9 or 31.0.1 or later.
What products are affected by CVE-2025-66552?
CVE-2025-66552 affects Nextcloud Server versions prior to 30.0.9 and 31.0.1 as well as Nextcloud Enterprise Server versions prior to 30.0.9 and 31.0.1.
What is the impact of CVE-2025-66552 on Nextcloud installations?
CVE-2025-66552 allows the admin_audit app to fail in logging actions on files and folders, potentially obscuring user activity.
Is CVE-2025-66552 exploitable remotely?
CVE-2025-66552 is not directly exploitable as it concerns internal logging of actions rather than an external attack vector.