Two-Factor Authentication Bypass in Nextcloud's WebAuthn Provider
CVE-2025-66558
What is CVE-2025-66558?
The Nextcloud Twofactor WebAuthn component is exposed to a vulnerability due to a missing ownership check. Attackers can exploit this by correctly guessing a random string ranging from 80 to 128 characters, allowing them to take over a user's 2FA WebAuthn device. Users will face a prompt to register a new device upon their next login, potentially compromising their account security. This issue was addressed in versions 1.4.2 and 2.4.1, which correct the flawed ownership verification process.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
security-advisories < 1.4.2 < 1.4.2
security-advisories >= 2.0.0-beta.1, < 2.4.1 < 2.0.0-beta.1, 2.4.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved