Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.7 and 0.9.4, authenticated users were able to view meta data of columns in other tables of the Tables app by modifying the numeric ID in a request. This vulnerability is fixed in 0.8.7 and 0.9.4.
History

Fri, 05 Dec 2025 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Nextcloud
Nextcloud tables
Vendors & Products Nextcloud
Nextcloud tables

Fri, 05 Dec 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 05 Dec 2025 17:30:00 +0000

Type Values Removed Values Added
Description Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.7 and 0.9.4, authenticated users were able to view meta data of columns in other tables of the Tables app by modifying the numeric ID in a request. This vulnerability is fixed in 0.8.7 and 0.9.4.
Title Nextcloud Tables app allowed users to view columns metadata information of any table
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-12-05T17:18:09.776Z

Updated: 2025-12-05T18:44:14.388Z

Reserved: 2025-12-04T15:57:22.034Z

Link: CVE-2025-66553

cve-icon Vulnrichment

Updated: 2025-12-05T18:44:03.696Z

cve-icon NVD

Status : Received

Published: 2025-12-05T18:15:58.460

Modified: 2025-12-05T18:15:58.460

Link: CVE-2025-66553

cve-icon Redhat

No data.