# CVE-2025-66552

## Summary

- **CVE ID:** CVE-2025-66552
- **Severity:** MEDIUM
- **CVSS Score:** 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L)
- **CWE:** CWE-778
- **Published:** Dec 5, 2025
- **Last Modified:** Mar 13, 2026

## Description

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1, incorrect path handling with groupfolders caused the admin_audit app to not properly log all actions on files and folders inside groupfolders. This vulnerability is fixed in Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1.

## Affected Products

- nextcloud — security-advisories (>= 32.0.0beta1, < 32.0.1)
- nextcloud — security-advisories (< 31.0.9)

## References

- [CNA](https://github.com/nextcloud/security-advisories/security/advisories/GHSA-ww9m-f8j4-jj9x)
- [CNA](https://github.com/nextcloud/server/pull/50992)
- [CNA](https://github.com/nextcloud/server/commit/7cc005c43c72bc384848cf8cb851895827c412f6)
- [CNA](https://hackerone.com/reports/2890071)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.31%
- **EPSS Percentile:** 23.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._