Skip to main content
Vulnerability Database/CVE-2025-64011

CVE-2025-64011: Nextcloud Server IDOR Vulnerability

CVE-2025-64011 is an Insecure Direct Object Reference flaw in Nextcloud Server 30.0.0 that lets authenticated users access file previews belonging to other users. This article covers the technical details, affected versions, impact, and mitigation.

Published:

CVE-2025-64011 Overview

CVE-2025-64011 is an Insecure Direct Object Reference (IDOR) vulnerability in Nextcloud Server 30.0.0. The flaw resides in the /core/preview endpoint, which fails to validate ownership of the requested fileId parameter. Any authenticated user can request preview renderings of files belonging to other users without any sharing relationship. The issue is tracked under CWE-639: Authorization Bypass Through User-Controlled Key and affects confidentiality of stored documents and images on the platform.

Critical Impact

Authenticated users can retrieve previews of arbitrary files stored by other Nextcloud users, exposing text documents, images, and other sensitive content without authorization.

Affected Products

  • Nextcloud Server 30.0.0
  • Deployments exposing the /core/preview endpoint to authenticated users
  • Self-hosted and managed Nextcloud instances running the affected release

Discovery Timeline

  • 2025-12-12 - CVE-2025-64011 published to the National Vulnerability Database
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-64011

Vulnerability Analysis

The vulnerability stems from missing authorization checks in the Nextcloud preview generation pipeline. When a user requests /core/preview, the application accepts a numeric fileId parameter and returns a rendered preview of the referenced file. The handler does not verify that the authenticated session owns the target file or that the file has been shared with the requester. As a result, a logged-in user can iterate through fileId values and retrieve previews of documents belonging to other tenants on the same instance. The impact is bounded to confidentiality, since previews are read-only, but can expose sensitive text, images, and office documents.

Root Cause

The root cause is a broken access control pattern classified as [CWE-639]. The preview controller trusts a user-supplied object identifier without cross-referencing the authenticated principal against the file's access control list. Nextcloud's standard file access path enforces ownership and share membership, but the preview endpoint bypasses this check and resolves fileId directly against the storage layer.

Attack Vector

Exploitation requires low-privilege authenticated access to a vulnerable Nextcloud instance. An attacker enumerates fileId values by issuing authenticated HTTP GET requests to /core/preview?fileId=<id> and inspects responses for returned image data. No user interaction, elevated privileges, or special configuration is required. A proof-of-concept enumeration script is published as a GitHub Gist by the reporter, and additional details are available in a Google Drive write-up.

No verified exploit code is included here. See the referenced advisory links for technical reproduction details.

Detection Methods for CVE-2025-64011

Indicators of Compromise

  • High-volume authenticated GET requests to /core/preview from a single session with sequential or randomized fileId values
  • Preview requests returning HTTP 200 responses for fileId values not previously accessed through the file listing or sharing APIs
  • Unusual spikes in preview generation activity attributed to a single user account

Detection Strategies

  • Correlate /core/preview access logs against the requesting user's file ownership and share membership records to identify out-of-scope accesses
  • Baseline normal preview request rates per user and alert on statistical anomalies indicative of enumeration
  • Review web server and reverse proxy logs for brute-force style fileId iteration patterns

Monitoring Recommendations

  • Forward Nextcloud application logs and NGINX or Apache access logs to a centralized SIEM for correlation and retention
  • Enable Nextcloud audit logging (admin_audit app) to capture file access events alongside preview endpoint telemetry
  • Monitor authentication logs for newly created or compromised low-privilege accounts that may be used to stage enumeration

How to Mitigate CVE-2025-64011

Immediate Actions Required

  • Upgrade Nextcloud Server to a release that includes the authorization fix for the /core/preview endpoint beyond version 30.0.0
  • Restrict access to the Nextcloud instance to trusted users and audit existing accounts for unexpected provisioning
  • Review recent preview endpoint access logs for signs of enumeration prior to patching

Patch Information

Nextcloud addresses preview endpoint authorization issues in subsequent 30.x maintenance releases. Administrators should consult the Nextcloud official site and release notes for the specific patched build and apply the upgrade through the standard updater or distribution package.

Workarounds

  • Place the Nextcloud instance behind a web application firewall rule that rate-limits requests to /core/preview per authenticated session
  • Temporarily disable preview generation by setting enable_previews to false in config.php if an immediate upgrade is not possible
  • Limit account creation and reduce the authenticated attack surface until the patch is deployed
bash
# Configuration example: disable preview generation in Nextcloud config.php
sudo -u www-data php /var/www/nextcloud/occ config:system:set enable_previews --value=false --type=boolean

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.