CVE-2025-66556
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-12-05

Last updated on: 2025-12-09

Assigner: GitHub, Inc.

Description
Nextcloud talk is a video & audio conferencing app for Nextcloud. Prior to 20.1.8 and 21.1.2, a participant with chat permissions was able to delete poll drafts of other participants within the conversation based on their numeric ID. This vulnerability is fixed in 20.1.8 and 21.1.2.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-12-05
Last Modified
2025-12-09
Generated
2026-05-06
AI Q&A
2025-12-05
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
nextcloud talk From 20.0.0 (inc) to 20.1.8 (exc)
nextcloud talk From 21.0.0 (inc) to 21.1.2 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability in Nextcloud Talk allowed a participant who had chat permissions to delete poll drafts created by other participants within the conversation by exploiting the numeric ID of the drafts. This issue existed in versions prior to 20.1.8 and 21.1.2 and was fixed in those versions.


How can this vulnerability impact me? :

The vulnerability could allow a participant with chat permissions to delete poll drafts of other users, potentially disrupting communication or collaboration within the conversation. However, it does not impact confidentiality or availability, only integrity to a limited extent.


What immediate steps should I take to mitigate this vulnerability?

Update Nextcloud Talk to version 20.1.8 or 21.1.2 or later, as these versions contain the fix for this vulnerability.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart