← Vulnerability feed

Vulnerability record · CVE-2025-66551 · published 5 December 2025

CVE-2025-66551: Nextcloud tables insecure direct object reference vulnerability

Nextcloud · Tables

Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.6 and 0.9.3, a malicious user was able to create their own table and then move a column to a victims table. This vulnerability is fixed in 0.8.6 and 0.9.3.

4.3 CVSS 3.1 Medium EPSS 0.25% · top 84.9% CWE-639 · Insecure direct object reference
4.3CVSS 3.1 base score
0.25%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
25 Sep 2026Last modified by NVD

Description

Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.6 and 0.9.3, a malicious user was able to create their own table and then move a column to a victims table. This vulnerability is fixed in 0.8.6 and 0.9.3.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-66551 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.2CVE-2026-45545Nextcloud tables sql injection vulnerabilityNextcloud is an open source content collaboration platform. From versions 0.7.0 to before 0.7.7, 0.8.0 to before 0.8.10, 0.9.0 to before 0.9.8, and 1…EPSS 0.52%7.1CVE-2026-45722Nextcloud tables sql injection vulnerabilityNextcloud is an open source content collaboration platform. From versions 0.9.0 to before 0.9.7, and 1.0.0 to before 1.0.2, a missing sanitization in…EPSS 0.49%6.5CVE-2024-52511Nextcloud tables insecure direct object reference vulnerabilityNextcloud Tables allows users to to create tables with individual columns. By directly specifying the ID of a table or view, a malicious user could b…EPSS 0.46%5.3CVE-2025-66513Nextcloud tables insecure direct object reference vulnerabilityNextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.9, 0.9.6, and 1.0.1, the information which table (numeric…EPSS 0.30%4.3CVE-2026-45544Nextcloud tables vulnerabilityNextcloud is an open source content collaboration platform. From version 0.8.0 to before version 1.0.4, the view filter criteria is exposed to users …EPSS 0.37%4.3CVE-2025-66553Nextcloud tables insecure direct object reference vulnerabilityNextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.7 and 0.9.4, authenticated users were able to view meta d…EPSS 0.28%4.3CVE-2024-52507Nextcloud tables insecure direct object reference vulnerabilityNextcloud Tables allows users to to create tables with individual columns. The information which Table (numeric ID) is shared with which groups and u…EPSS 0.42%8.4CVE-2026-55255Langflow IDOR in responses endpoint allows cross-user flow executionLangflow before 1.9.1 has an insecure direct object reference in the /api/v1/responses endpoint. An authenticated attacker can supply another user's …KEVEPSS 0.89%analysed

Source: NIST National Vulnerability Database (record CVE-2025-66551), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.