CVE-2025-64011 Overview
CVE-2025-64011 is an Insecure Direct Object Reference (IDOR) vulnerability in Nextcloud Server 30.0.0. The flaw resides in the /core/preview endpoint, which fails to validate ownership of the requested fileId parameter. Any authenticated user can request preview renderings of files belonging to other users without any sharing relationship. The issue is tracked under CWE-639: Authorization Bypass Through User-Controlled Key and affects confidentiality of stored documents and images on the platform.
Critical Impact
Authenticated users can retrieve previews of arbitrary files stored by other Nextcloud users, exposing text documents, images, and other sensitive content without authorization.
Affected Products
- Nextcloud Server 30.0.0
- Deployments exposing the /core/preview endpoint to authenticated users
- Self-hosted and managed Nextcloud instances running the affected release
Discovery Timeline
- 2025-12-12 - CVE-2025-64011 published to the National Vulnerability Database
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-64011
Vulnerability Analysis
The vulnerability stems from missing authorization checks in the Nextcloud preview generation pipeline. When a user requests /core/preview, the application accepts a numeric fileId parameter and returns a rendered preview of the referenced file. The handler does not verify that the authenticated session owns the target file or that the file has been shared with the requester. As a result, a logged-in user can iterate through fileId values and retrieve previews of documents belonging to other tenants on the same instance. The impact is bounded to confidentiality, since previews are read-only, but can expose sensitive text, images, and office documents.
Root Cause
The root cause is a broken access control pattern classified as [CWE-639]. The preview controller trusts a user-supplied object identifier without cross-referencing the authenticated principal against the file's access control list. Nextcloud's standard file access path enforces ownership and share membership, but the preview endpoint bypasses this check and resolves fileId directly against the storage layer.
Attack Vector
Exploitation requires low-privilege authenticated access to a vulnerable Nextcloud instance. An attacker enumerates fileId values by issuing authenticated HTTP GET requests to /core/preview?fileId=<id> and inspects responses for returned image data. No user interaction, elevated privileges, or special configuration is required. A proof-of-concept enumeration script is published as a GitHub Gist by the reporter, and additional details are available in a Google Drive write-up.
No verified exploit code is included here. See the referenced advisory links for technical reproduction details.
Detection Methods for CVE-2025-64011
Indicators of Compromise
- High-volume authenticated GET requests to /core/preview from a single session with sequential or randomized fileId values
- Preview requests returning HTTP 200 responses for fileId values not previously accessed through the file listing or sharing APIs
- Unusual spikes in preview generation activity attributed to a single user account
Detection Strategies
- Correlate /core/preview access logs against the requesting user's file ownership and share membership records to identify out-of-scope accesses
- Baseline normal preview request rates per user and alert on statistical anomalies indicative of enumeration
- Review web server and reverse proxy logs for brute-force style fileId iteration patterns
Monitoring Recommendations
- Forward Nextcloud application logs and NGINX or Apache access logs to a centralized SIEM for correlation and retention
- Enable Nextcloud audit logging (admin_audit app) to capture file access events alongside preview endpoint telemetry
- Monitor authentication logs for newly created or compromised low-privilege accounts that may be used to stage enumeration
How to Mitigate CVE-2025-64011
Immediate Actions Required
- Upgrade Nextcloud Server to a release that includes the authorization fix for the /core/preview endpoint beyond version 30.0.0
- Restrict access to the Nextcloud instance to trusted users and audit existing accounts for unexpected provisioning
- Review recent preview endpoint access logs for signs of enumeration prior to patching
Patch Information
Nextcloud addresses preview endpoint authorization issues in subsequent 30.x maintenance releases. Administrators should consult the Nextcloud official site and release notes for the specific patched build and apply the upgrade through the standard updater or distribution package.
Workarounds
- Place the Nextcloud instance behind a web application firewall rule that rate-limits requests to /core/preview per authenticated session
- Temporarily disable preview generation by setting enable_previews to false in config.php if an immediate upgrade is not possible
- Limit account creation and reduce the authenticated attack surface until the patch is deployed
# Configuration example: disable preview generation in Nextcloud config.php
sudo -u www-data php /var/www/nextcloud/occ config:system:set enable_previews --value=false --type=boolean
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.