Nextcloud Server 30.0.0 is vulnerable to an Insecure Direct Object Reference (IDOR) in the /core/preview endpoint. Any authenticated user can access previews of arbitrary files belonging to other users by manipulating the fileId parameter. This allows unauthorized disclosure of sensitive data, such as text files or images, without prior sharing permissions.
History

Sun, 14 Dec 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Nextcloud
Nextcloud server
Vendors & Products Nextcloud
Nextcloud server

Fri, 12 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 12 Dec 2025 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Fri, 12 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
Description Nextcloud Server 30.0.0 is vulnerable to an Insecure Direct Object Reference (IDOR) in the /core/preview endpoint. Any authenticated user can access previews of arbitrary files belonging to other users by manipulating the fileId parameter. This allows unauthorized disclosure of sensitive data, such as text files or images, without prior sharing permissions.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-12-12T00:00:00.000Z

Updated: 2025-12-12T19:12:34.083Z

Reserved: 2025-10-27T00:00:00.000Z

Link: CVE-2025-64011

cve-icon Vulnrichment

Updated: 2025-12-12T19:12:06.395Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-12T17:15:45.210

Modified: 2025-12-15T18:22:40.637

Link: CVE-2025-64011

cve-icon Redhat

No data.