CVE-2025-66551 Overview
CVE-2025-66551 is an authorization flaw in Nextcloud Tables, a Nextcloud app that lets users create custom tables with individual columns. In versions prior to 0.8.6 and 0.9.3, an authenticated user could create their own table and then move a column from that table into another user's table. The flaw stems from missing ownership validation on column relocation operations [CWE-639: Authorization Bypass Through User-Controlled Key]. Nextcloud fixed the issue in Tables 0.8.6 and 0.9.3.
Critical Impact
An authenticated attacker can inject arbitrary columns into tables owned by other users, corrupting data structure integrity without needing elevated privileges.
Affected Products
- Nextcloud Tables versions prior to 0.8.6
- Nextcloud Tables versions prior to 0.9.3
- Nextcloud instances with the Tables app enabled
Discovery Timeline
- 2025-12-05 - CVE-2025-66551 published to NVD
- 2026-09-25 - Last updated in NVD database
Technical Details for CVE-2025-66551
Vulnerability Analysis
The vulnerability resides in the Tables API controller responsible for column update operations. The columnService->update method accepted a table identifier parameter alongside the column identifier without verifying that the requesting user owned or had write access to the destination table. This allowed a malicious authenticated user to submit an update request that reassigned one of their own columns to a table belonging to another user.
Because the operation is scoped to authenticated users with existing table-creation rights, exploitation requires only a valid Nextcloud account. The impact is limited to integrity of victim tables; the vulnerability does not disclose confidential data or crash the service.
Root Cause
The root cause is missing authorization enforcement on the destination resource during a column move operation, classified as [CWE-639]. The API relied on the caller-supplied table identifier without cross-checking ownership or share permissions on that target table.
Attack Vector
Exploitation occurs over the network against an authenticated session. The attacker creates a table they own, adds one or more columns, then issues a column-update API request specifying the victim's tableId. The server accepts the reassignment and the column appears in the victim's table structure.
// Security patch in lib/Controller/Api1Controller.php
// The vulnerable call passed a nullable tableId parameter to columnService->update
// The patch removes that parameter, preventing cross-table column relocation.
try {
$item = $this->columnService->update(
$columnId,
- null,
$this->userId,
new ColumnDto(
title: $title,
Source: Nextcloud Tables commit 39f24a6
Detection Methods for CVE-2025-66551
Indicators of Compromise
- Unexpected columns appearing in tables owned by legitimate users, particularly columns whose creator field references a different account.
- API request logs showing PUT or update operations against /api/1/columns/{columnId} that reference a tableId not owned by the requesting user.
- Audit-log entries where column ownership and table ownership fields diverge after a column update event.
Detection Strategies
- Review Nextcloud Tables audit logs for column update events and correlate the acting user against the destination table owner.
- Query the Tables database schema for columns whose created_by value does not match any user with share access to the parent table.
- Alert on repeated column-update API calls originating from accounts that recently created and populated tables of their own.
Monitoring Recommendations
- Enable Nextcloud application logging at the info level for the Tables app and ship logs to a centralized SIEM.
- Track the installed Tables app version across all Nextcloud servers and flag any instance below 0.8.6 or 0.9.3.
- Monitor HackerOne report #3137895 and the Nextcloud security advisory GHSA-w787-vwqp-8wr7 for follow-up disclosures.
How to Mitigate CVE-2025-66551
Immediate Actions Required
- Upgrade Nextcloud Tables to version 0.8.6 or 0.9.3, matching the supported branch for your Nextcloud release.
- Audit existing tables for foreign columns introduced before patching and remove any that were not authorized by the table owner.
- Notify Nextcloud users about the issue so they can review their tables for unexpected structural changes.
Patch Information
The fix is delivered in Nextcloud Tables 0.8.6 and 0.9.3. Technical details are available in pull request #1810 and the corresponding commit 39f24a6. The patch removes the caller-controlled destination tableId parameter from the column update path, eliminating the cross-table move capability.
Workarounds
- If patching cannot be performed immediately, disable the Tables app via occ app:disable tables until the upgrade is applied.
- Restrict the Tables app to trusted user groups using Nextcloud's app-enable-for-groups setting to reduce the population of potential attackers.
# Upgrade Nextcloud Tables via the occ command
sudo -u www-data php occ app:update tables
# Verify the installed version meets the fixed release
sudo -u www-data php occ app:list | grep -A1 tables
# Temporary workaround: disable the Tables app until patched
sudo -u www-data php occ app:disable tables
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.