Multitenant Access Vulnerability in Nextcloud Server by Nextcloud
CVE-2025-47794

2.6LOW

Key Information:

Vendor

Nextcloud

Vendor
CVE Published:
16 May 2025

What is CVE-2025-47794?

Nextcloud Server and Nextcloud Enterprise Server prior to specified versions are vulnerable to a multitenant access issue. An attacker on a multi-user system may exploit this vulnerability to read sensitive temporary files created by other users or perform symlink attacks, compromising user data integrity and confidentiality. Users are advised to upgrade to the patched versions to mitigate the risk associated with this vulnerability, as no workarounds are currently available.

Affected Version(s)

security-advisories >= 26.0.0, < 26.0.13.13 < 26.0.0, 26.0.13.13

security-advisories >= 27.0.0, < 27.1.11.13 < 27.0.0, 27.1.11.13

security-advisories >= 28.0.0, < 28.0.14.4 < 28.0.0, 28.0.14.4

References

CVSS V3.1

Score:
2.6
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-47794 : Multitenant Access Vulnerability in Nextcloud Server by Nextcloud