Skip to main content
Vulnerability Database/CVE-2025-66545

CVE-2025-66545: Nextcloud Group Folders Privilege Escalation

CVE-2025-66545 is a privilege escalation flaw in Nextcloud Group Folders that allows read-only users to restore files from trash. This article covers the technical details, affected versions, security impact, and mitigation steps.

Published:

CVE-2025-66545 Overview

CVE-2025-66545 affects Nextcloud Groupfolders, the application that provides admin-configured folders shared across groups or teams. A user with read-only permission on a group folder can restore a file from the trash bin, bypassing the intended access control model. The flaw stems from an incorrect permission check that evaluates the trash item's path rather than the target restore path. Nextcloud fixed the issue in Groupfolders versions 14.0.11, 15.3.12, 16.0.15, 17.0.14, 18.1.8, 19.1.8, and 20.1.2. The weakness is classified under [CWE-707] (Improper Neutralization) and impacts integrity of shared group folders.

Critical Impact

Authenticated users granted read-only access to a Groupfolder can modify folder contents by restoring trashed files, breaking the permission model expected by administrators.

Affected Products

  • Nextcloud Groupfolders prior to 14.0.11
  • Nextcloud Groupfolders 15.x prior to 15.3.12, 16.x prior to 16.0.15, 17.x prior to 17.0.14
  • Nextcloud Groupfolders 18.x prior to 18.1.8, 19.x prior to 19.1.8, and 20.x prior to 20.1.2

Discovery Timeline

  • 2025-12-05 - CVE-2025-66545 published to the National Vulnerability Database (NVD)
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-66545

Vulnerability Analysis

Groupfolders enforces per-user permissions on folder contents, including read, update, create, delete, and share. The trash restore workflow is expected to require PERMISSION_UPDATE on the destination path where the file will reappear. Instead, the pre-patch code checked the permission against $item->getPath(), which reflects the location the file occupied before deletion inside the trash context. That path does not always match the actual restore target, so a user holding only read permission on the destination folder could still pass the check and complete the restore. The result is a broken access-control primitive: read-only collaborators can reintroduce arbitrary previously-deleted files into a shared folder, altering shared state without authorization.

Root Cause

The root cause is an improper permission check in lib/Trash/TrashBackend.php. The check evaluated the wrong path object, so authorization was granted based on the trash item's stored path rather than the real filesystem location the restore would write to. The fix substitutes $this->getUnJailedPath($node) to validate the true target path before allowing the operation.

Attack Vector

Exploitation requires an authenticated Nextcloud account with at least read-only membership in a Groupfolder that contains items in the trash. The attacker issues the standard trash-restore request through the Nextcloud web interface or WebDAV API. Because the pre-patch check misidentifies the path being written to, the request succeeds and the file reappears in the shared folder despite the account lacking update rights.

php
// Security patch in lib/Trash/TrashBackend.php
// Merge pull request #4076 - fix/trash/restore-correct-path-stable31

            throw new NotFoundException();
        }

-       if (!$this->userHasAccessToPath($item->getUser(), $item->getPath(), Constants::PERMISSION_UPDATE)) {
+       if (!$this->userHasAccessToPath($item->getUser(), $this->getUnJailedPath($node), Constants::PERMISSION_UPDATE)) {
            throw new NotPermittedException();
        }

Source: Nextcloud Groupfolders commit bbe87eb

Detection Methods for CVE-2025-66545

Indicators of Compromise

  • Trash restore events in Nextcloud audit logs performed by accounts whose Groupfolder membership grants only read permission.
  • Unexpected reappearance of previously deleted files in Groupfolders without a corresponding administrative or owner action.
  • WebDAV MOVE requests targeting the /trashbin/ endpoint originating from low-privilege user sessions.

Detection Strategies

  • Correlate Nextcloud admin_audit events for file_restored with each actor's effective permissions on the destination Groupfolder path.
  • Alert when a user without PERMISSION_UPDATE (bit 2) generates a successful restore action against a folder they only read.
  • Review the Groupfolders installed version reported by occ app:list groupfolders against the fixed release list.

Monitoring Recommendations

  • Ship Nextcloud application and audit logs into a centralized logging platform and retain them for permission-anomaly review.
  • Establish a baseline of normal trash restore actors per Groupfolder and alert on new low-privilege actors.
  • Monitor GitHub advisory feeds for Nextcloud so new Groupfolders CVEs are triaged as they publish.

How to Mitigate CVE-2025-66545

Immediate Actions Required

  • Upgrade Groupfolders to 14.0.11, 15.3.12, 16.0.15, 17.0.14, 18.1.8, 19.1.8, or 20.1.2, matching the branch that aligns with your Nextcloud server version.
  • Audit recent trash-restore activity across all Groupfolders and revert any restores performed by read-only users.
  • Review Groupfolder permission assignments and remove read-only grants that are no longer required.

Patch Information

Nextcloud published the fix in GitHub Security Advisory GHSA-2vrq-fhmf-c49m. The code change is delivered in Pull Request #4076 and merged as commit bbe87eb, which corrects the path evaluated by userHasAccessToPath in TrashBackend.php.

Workarounds

  • Disable the Groupfolders trash feature until the patched version can be deployed, so restore actions are not available to any user.
  • Restrict Groupfolder membership so accounts that should not modify content are removed from folders holding sensitive data.
  • Use file-level auditing to rapidly detect and roll back unauthorized restore actions if patching must be delayed.
bash
# Upgrade Groupfolders using the Nextcloud occ CLI
sudo -u www-data php occ app:update groupfolders

# Verify the installed version matches a patched release
sudo -u www-data php occ app:list | grep -A1 groupfolders

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.