Insecure Direct Object Reference in Nextcloud Server
CVE-2025-64011

4.3MEDIUM

Key Information:

Vendor

Nextcloud

Vendor
CVE Published:
12 December 2025

What is CVE-2025-64011?

Nextcloud Server version 30.0.0 offers a security risk through an Insecure Direct Object Reference within the /core/preview endpoint. Authenticated users can exploit this vulnerability by altering the fileId parameter, gaining access to file previews belonging to other users without appropriate permission. This flaw facilitates unauthorized data exposure, potentially revealing sensitive information such as documents and images, creating significant privacy and security concerns.

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.