CVE-2025-66510 Details
Description
Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 31.0.10 and 32.0.1 and Nextcloud Enterprise Server prior to 28.0.14.11, 29.0.16.8, 30.0.17.3, and 31.0.10, contacts search allowed to retrieve personal data of other users (emails, names, identifiers) without proper access control. This allows an authenticated user to retrieve information about accounts that are not related or added as contacts.
A vulnerability in Nextcloud Server versions prior to 31.0.10 and 32.0.1, as well as in Nextcloud Enterprise Server versions prior to 28.0.14.11, 29.0.16.8, 30.0.17.3, and 31.0.10, allows authenticated users to access personal data of other users through the contacts search feature. This includes emails, names, and identifiers, without proper access control. The issue arises because the system address book is exposed in the response, even when the 'dav.system_addressbook_exposed' configuration is set to 'no'.
Users are advised to update Nextcloud Server to version 31.0.10 or 32.0.1, and Nextcloud Enterprise Server to versions 28.0.14.11, 29.0.16.8, 30.0.17.3 or 31.0.10.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 5, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-359 | Exposure of Private Personal Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| nextcloud nextcloud server | >= 28.0.0, < 28.0.14.11 >= 29.0.0, < 29.0.16.8 >= 30.0.0, < 30.0.17.3 >= 31.0.0, < 31.0.10 >= 32.0.0, < 32.0.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 10, 2025 | Initial Analysis | [email protected] |
| Dec 5, 2025 | New CVE Received | [email protected] |