CVE-2025-66547 Overview
CVE-2025-66547 affects Nextcloud Server and Nextcloud Enterprise Server versions prior to 31.0.1. The flaw allows non-privileged authenticated users to modify tags on files they should not have access to by abusing the bulk tagging functionality. The weakness is classified as an authorization issue through user-controlled key [CWE-639]. Nextcloud resolved the issue in version 31.0.1 by introducing a TagUpdateForbiddenException and tightening checks in the WebDAV SystemTag plugin.
Critical Impact
Authenticated low-privileged users can alter metadata on restricted files via bulk tagging, enabling cross-tenant tag manipulation and potential disruption of tag-driven workflows such as retention, sharing, and access policies.
Affected Products
- Nextcloud Server versions prior to 31.0.1
- Nextcloud Enterprise Server versions prior to 31.0.1
- Deployments relying on systemtags for access or retention workflows
Discovery Timeline
- 2025-12-05 - CVE-2025-66547 published to the National Vulnerability Database
- 2026-06-17 - Last updated in the NVD database
Technical Details for CVE-2025-66547
Vulnerability Analysis
The vulnerability resides in the WebDAV extension that handles system tag operations, specifically apps/dav/lib/SystemTag/SystemTagPlugin.php. Nextcloud exposes bulk tagging through its DAV endpoints to let users apply tags to multiple files in a single request. The server failed to validate whether the requesting user had sufficient access to each targeted file during bulk operations.
As a result, a non-privileged account could submit a bulk tag update referencing file object identifiers that belong to other users or shares the account cannot read. Tag modifications would succeed despite the lack of underlying file permissions. This breaks the authorization boundary Nextcloud enforces for file metadata.
Root Cause
The root cause is an authorization gap in the system tag update path. The DAV plugin did not raise a forbidden exception when a caller lacked permission to modify tags on a given object. The patch adds TagUpdateForbiddenException handling and switches the admin-restriction configuration lookup from a loose string comparison to a strict boolean via getValueBool, closing a secondary logic flaw in restrict_creation_to_admin.
Attack Vector
Exploitation requires an authenticated session on a vulnerable Nextcloud instance. The attacker issues a bulk tag update over WebDAV referencing file identifiers of inaccessible objects. No user interaction is required from the file owner. The impact is limited to integrity of tag metadata; file contents remain confidential and available.
// Patch excerpt: apps/dav/lib/SystemTag/SystemTagPlugin.php
use OCP\SystemTag\ISystemTagObjectMapper;
use OCP\SystemTag\TagAlreadyExistsException;
use OCP\SystemTag\TagCreationForbiddenException;
+use OCP\SystemTag\TagUpdateForbiddenException;
use OCP\Util;
use Sabre\DAV\Exception\BadRequest;
use Sabre\DAV\Exception\Conflict;
Source: Nextcloud server commit b44f156
// Patch excerpt: apps/settings/lib/Settings/Admin/Server.php
- $this->initialStateService->provideInitialState('restrictSystemTagsCreationToAdmin', $this->appConfig->getValueString('systemtags', 'restrict_creation_to_admin', 'true'));
+ $this->initialStateService->provideInitialState('restrictSystemTagsCreationToAdmin', $this->appConfig->getValueBool('systemtags', 'restrict_creation_to_admin', false));
Source: Nextcloud server commit b44f156
Detection Methods for CVE-2025-66547
Indicators of Compromise
- Unexpected changes to oc_systemtag_object_mapping records involving file IDs the acting user does not own or have shared access to.
- WebDAV PROPPATCH or bulk tagging requests from standard user accounts referencing object IDs outside their file tree.
- Nextcloud audit log entries showing tag assignments or removals performed by users without read permission on the target file.
Detection Strategies
- Enable the Nextcloud admin_audit app and alert on systemtags events where actor user ID does not match the file owner or share grantee.
- Correlate WebDAV access logs with file ACLs to identify tag write operations against objects the user cannot GET.
- Hunt for high-volume bulk tagging activity from non-administrator accounts within short time windows.
Monitoring Recommendations
- Forward Nextcloud application and audit logs to a central SIEM for retention and correlation.
- Baseline normal tagging behavior per user role and alert on deviations in object-ID distribution.
- Review tag-driven automation such as retention rules and share policies for unauthorized modifications after upgrade.
How to Mitigate CVE-2025-66547
Immediate Actions Required
- Upgrade all Nextcloud Server and Enterprise Server instances to version 31.0.1 or later.
- Audit oc_systemtag_object_mapping for recent entries created by non-privileged users and reconcile against expected tag workflows.
- Review any downstream processes that rely on system tags, including retention, flows, and shared workspace rules.
Patch Information
The fix is delivered in Nextcloud Server 31.0.1 and introduces TagUpdateForbiddenException in the DAV SystemTagPlugin. Full details are published in the Nextcloud GHSA-hq6c-r898-fgf2 advisory, the upstream commit b44f156, and the HackerOne report #3040887.
Workarounds
- Restrict system tag creation and assignment to administrators by setting the systemtagsrestrict_creation_to_admin option to true until patching is complete.
- Temporarily disable bulk tagging features for non-administrative roles where feasible.
- Limit WebDAV access to trusted networks or require stronger authentication for tagging endpoints during the remediation window.
# Enforce admin-only system tag creation as an interim control
sudo -u www-data php occ config:app:set systemtags restrict_creation_to_admin --value="true"
# Verify the Nextcloud version is 31.0.1 or later
sudo -u www-data php occ status | grep versionstring
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.