Multitenant Access Vulnerability in Nextcloud Server by Nextcloud
CVE-2025-47794
2.6LOW
What is CVE-2025-47794?
Nextcloud Server and Nextcloud Enterprise Server prior to specified versions are vulnerable to a multitenant access issue. An attacker on a multi-user system may exploit this vulnerability to read sensitive temporary files created by other users or perform symlink attacks, compromising user data integrity and confidentiality. Users are advised to upgrade to the patched versions to mitigate the risk associated with this vulnerability, as no workarounds are currently available.
Affected Version(s)
security-advisories >= 26.0.0, < 26.0.13.13 < 26.0.0, 26.0.13.13
security-advisories >= 27.0.0, < 27.1.11.13 < 27.0.0, 27.1.11.13
security-advisories >= 28.0.0, < 28.0.14.4 < 28.0.0, 28.0.14.4