Skip to main content

Insufficient Logging

CVE-2025-66552

Severity Medium
Score 4.3/10

Summary

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1, incorrect path handling with groupfolders caused the admin_audit app to not properly log all actions on files and folders inside groupfolders. This vulnerability is fixed in Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • LOW
  • NONE
  • LOW

CWE-778 - Insufficient Logging

When a security-critical event occurs, the software either does not record the event or omits important details about the event when logging it.

References

Advisory Timeline

  • Published