Nextcloud talk is a video & audio conferencing app for Nextcloud. Prior to 20.1.8 and 21.1.2, a participant with chat permissions was able to delete poll drafts of other participants within the conversation based on their numeric ID. This vulnerability is fixed in 20.1.8 and 21.1.2.
History

Fri, 05 Dec 2025 18:15:00 +0000

Type Values Removed Values Added
Description Nextcloud talk is a video & audio conferencing app for Nextcloud. Prior to 20.1.8 and 21.1.2, a participant with chat permissions was able to delete poll drafts of other participants within the conversation based on their numeric ID. This vulnerability is fixed in 20.1.8 and 21.1.2.
Title Nextcloud talk allows participants to blindly delete poll drafts of other users by ID
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-12-05T17:56:44.463Z

Updated: 2025-12-05T18:09:34.326Z

Reserved: 2025-12-04T16:01:32.472Z

Link: CVE-2025-66556

cve-icon Vulnrichment

Updated: 2025-12-05T18:09:05.662Z

cve-icon NVD

Status : Received

Published: 2025-12-05T18:15:58.803

Modified: 2025-12-05T18:15:58.803

Link: CVE-2025-66556

cve-icon Redhat

No data.