Nextcloud Server Admin_Audit Logging Flaw (30.0.8, 31.0.0)
CVE-2025-66552 Published on December 5, 2025
Nextcloud Server admin_audit does not log all actions on files in groupfolders
Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1, incorrect path handling with groupfolders caused the admin_audit app to not properly log all actions on files and folders inside groupfolders. This vulnerability is fixed in Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1.
Vulnerability Analysis
CVE-2025-66552 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a small impact on availability.
Weakness Type
Insufficient Logging
When a security-critical event occurs, the software either does not record the event or omits important details about the event when logging it. When security-critical events are not logged properly, such as a failed login attempt, this can make malicious behavior more difficult to detect and may hinder forensic analysis after an attack succeeds.
Products Associated with CVE-2025-66552
Want to know whenever a new CVE is published for Nextcloud? stack.watch will email you.
Affected Versions
nextcloud security-advisories:- Version >= 32.0.0beta1, < 32.0.1 is affected.
- Version < 31.0.9 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.