{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "cpe": [
              "cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*",
              "cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*"
            ],
            "extracted_events": [
              {
                "introduced": "30.0.0"
              },
              {
                "fixed": "30.0.9"
              },
              {
                "introduced": "31.0.0"
              },
              {
                "fixed": "31.0.1"
              }
            ],
            "source": [
              "CPE_RANGE",
              "REFERENCES"
            ]
          },
          "events": [
            {
              "introduced": "656488893e2175e19fbe273d76a5e16a598000c7"
            },
            {
              "fixed": "8c428e22e4823b3df1870264fb7169ffd154118e"
            },
            {
              "introduced": "051e46a7a272300cf7c90b3e330fd1501fd6a996"
            },
            {
              "fixed": "ca86133382c6efb7c0eb82e5b9806a84bad2b9dc"
            },
            {
              "fixed": "7cc005c43c72bc384848cf8cb851895827c412f6"
            }
          ],
          "repo": "https://github.com/nextcloud/server",
          "type": "GIT"
        }
      ]
    }
  ],
  "aliases": [
    "GHSA-ww9m-f8j4-jj9x"
  ],
  "database_specific": {
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
      "CWE-778"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66552.json"
  },
  "details": "Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1, incorrect path handling with groupfolders caused the admin_audit app to not properly log all actions on files and folders inside groupfolders. This vulnerability is fixed in Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1.",
  "id": "CVE-2025-66552",
  "modified": "2026-08-12T03:51:45.526408996Z",
  "published": "2025-12-05T16:36:39.749Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://hackerone.com/reports/2890071"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66552.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/nextcloud/security-advisories/security/advisories/GHSA-ww9m-f8j4-jj9x"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-66552"
    },
    {
      "type": "FIX",
      "url": "https://github.com/nextcloud/server/commit/7cc005c43c72bc384848cf8cb851895827c412f6"
    },
    {
      "type": "FIX",
      "url": "https://github.com/nextcloud/server/pull/50992"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
      "type": "CVSS_V3"
    }
  ],
  "summary": "Nextcloud Server admin_audit does not log all actions on files in groupfolders"
}