Nextcloud Tables Vulnerability Allows Unauthorized Table Manipulation
CVE-2025-66551

6.3MEDIUM

Key Information:

Vendor

Nextcloud

Vendor
CVE Published:
5 December 2025

What is CVE-2025-66551?

The Nextcloud Tables feature allows users to create and manage custom tables. However, in versions prior to 0.8.6 and 0.9.3, a vulnerability was identified that enables a malicious user to create their own table and subsequently transfer columns to another user's table, thereby compromising data integrity and security. This issue has been addressed in the updated releases.

Affected Version(s)

security-advisories >= 0.9.0-beta.1, < 0.9.3 < 0.9.0-beta.1, 0.9.3

security-advisories < 0.8.6 < 0.8.6

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-66551 : Nextcloud Tables Vulnerability Allows Unauthorized Table Manipulation