CVE-2025-66552 Overview
CVE-2025-66552 is an insufficient logging vulnerability [CWE-778] in Nextcloud Server and Enterprise Server. The flaw affects the admin_audit application, which fails to properly record user actions on files and folders stored inside groupfolders. The root cause is incorrect path handling within the audit event listeners. An authenticated user operating within a groupfolder can perform file actions that bypass the audit log, undermining accountability and forensic review. Nextcloud addressed the issue in Server and Enterprise Server versions 30.0.9 and 31.0.1.
Critical Impact
Administrators lose visibility into file operations performed within groupfolders, impairing incident response, compliance auditing, and insider threat detection.
Affected Products
- Nextcloud Server versions prior to 30.0.9
- Nextcloud Server versions prior to 31.0.1
- Nextcloud Enterprise Server (same version ranges)
Discovery Timeline
- 2025-12-05 - CVE-2025-66552 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-66552
Vulnerability Analysis
The admin_audit app in Nextcloud subscribes to file events and writes structured log entries describing user activity. When a file resides inside a groupfolder, the audit listener constructs the path field by trimming a fixed-length prefix from the node's internal path using mb_substr($node->getInternalPath(), 5). This hard-coded offset assumes the standard user files/ prefix. Groupfolder nodes do not share that layout, so the trimmed string produces incorrect or malformed paths. In some execution paths, the mismatch causes the audit entry to be dropped or logged with unusable context. The result is incomplete audit coverage for any create, read, update, delete, or preview action targeting groupfolder content.
Root Cause
The underlying weakness is improper path resolution in audit event handling [CWE-778]. The listeners hard-coded a user-storage path layout and did not account for alternate mount points such as groupfolders. Operations on groupfolder nodes therefore evaded structured logging.
Attack Vector
An authenticated low-privileged user with access to a groupfolder can perform file actions without generating complete audit records. The attack requires network access to the Nextcloud instance and valid credentials. No user interaction from an administrator is required.
// Patch excerpt - apps/admin_audit/lib/Actions/Files.php
$node = $event->getNode();
$params = [
'id' => $node instanceof NonExistingFile ? null : $node->getId(),
- 'path' => mb_substr($node->getInternalPath(), 5),
+ 'path' => $node->getPath(),
];
// Source: https://github.com/nextcloud/server/commit/7cc005c43c72bc384848cf8cb851895827c412f6
// Patch excerpt - apps/admin_audit/lib/Listener/FileEventListener.php
'height' => $event->getHeight(),
'crop' => $event->isCrop(),
'mode' => $event->getMode(),
-'path' => mb_substr($file->getInternalPath(), 5)
+'path' => $file->getPath(),
];
// Source: https://github.com/nextcloud/server/commit/7cc005c43c72bc384848cf8cb851895827c412f6
The fix replaces the hard-coded mb_substr call with $node->getPath(), which returns a canonical path valid for both user storage and groupfolder mounts.
Detection Methods for CVE-2025-66552
Indicators of Compromise
- Audit log entries in admin_audit.log containing truncated, empty, or malformed path values for events sourced from groupfolder activity.
- Gaps between file-system state in a groupfolder (new, modified, or deleted files) and corresponding entries in the audit log.
- Preview access events referencing files that have no matching create or upload record in the audit stream.
Detection Strategies
- Correlate Nextcloud application logs with admin_audit output to identify groupfolder operations that produced no audit entry.
- Compare file system change timestamps on groupfolder storage with the volume of audit events for the same window.
- Run periodic reviews of audit output for records with suspicious path fields and investigate the originating user session.
Monitoring Recommendations
- Forward Nextcloud admin_audit logs to a centralized SIEM or data lake for structured query and retention.
- Alert on sustained drops in audit event volume following a Nextcloud upgrade or groupfolder deployment.
- Baseline per-user groupfolder activity rates and investigate deviations that suggest unlogged operations.
How to Mitigate CVE-2025-66552
Immediate Actions Required
- Upgrade Nextcloud Server and Enterprise Server to version 30.0.9, 31.0.1, or later.
- Review historical admin_audit logs covering groupfolder usage and treat the window as incomplete for compliance purposes.
- Restrict groupfolder write access to trusted users until the patch is applied.
Patch Information
The fix is tracked in Nextcloud pull request #50992 and commit 7cc005c43c72bc384848cf8cb851895827c412f6. Refer to the Nextcloud GitHub Security Advisory GHSA-ww9m-f8j4-jj9x, the upstream commit, and the HackerOne report #2890071 for full technical details.
Workarounds
- No official workaround removes the logging gap; upgrading to a patched release is required.
- As a compensating control, enable file-system-level auditing on the underlying groupfolder storage path to capture activity outside the application layer.
- Restrict access to groupfolders through group membership and share permissions to reduce the user population that can trigger unlogged events.
# Upgrade using the Nextcloud updater (example)
sudo -u www-data php /var/www/nextcloud/updater/updater.phar
sudo -u www-data php /var/www/nextcloud/occ upgrade
sudo -u www-data php /var/www/nextcloud/occ status
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.