CVE-2025-66556 Overview
Nextcloud Talk is a video and audio conferencing application for the Nextcloud collaboration platform. CVE-2025-66556 is an Insecure Direct Object Reference (IDOR) vulnerability [CWE-639] in the poll management functionality. Prior to versions 20.1.8 and 21.1.2, any conversation participant holding chat permissions could delete poll drafts belonging to other participants by referencing the drafts' numeric identifiers. The flaw stems from missing authorization checks in the poll deletion controller. Nextcloud fixed the issue in Talk versions 20.1.8 and 21.1.2 by restricting draft management to moderators.
Critical Impact
Authenticated participants with chat permissions can enumerate and delete other users' poll drafts within a conversation, causing data loss and disrupting collaboration workflows.
Affected Products
- Nextcloud Talk versions prior to 20.1.8
- Nextcloud Talk versions 21.0.0 through 21.1.1
- Nextcloud Spreed (the underlying application repository)
Discovery Timeline
- 2025-12-05 - CVE-2025-66556 published to the National Vulnerability Database
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-66556
Vulnerability Analysis
The vulnerability resides in lib/Controller/PollController.php within the Nextcloud Spreed codebase. When handling deletion requests for poll drafts, the controller retrieved the target poll by its numeric identifier and proceeded to delete it without verifying that the requesting participant owned the draft or held moderator privileges. Any participant with basic chat permissions could iterate through numeric poll IDs and remove drafts created by other users in the same conversation. The impact is limited to integrity loss of poll draft records; confidentiality and availability of the broader Nextcloud instance remain intact.
Root Cause
The underlying weakness is a missing authorization check on a user-supplied object reference, classified as [CWE-639] Authorization Bypass Through User-Controlled Key. The deleteDraft code path trusted the numeric poll ID supplied by the client and did not verify participant ownership or moderator status before executing pollService->deleteByPollId().
Attack Vector
Exploitation requires an authenticated account that is a participant in the target conversation and holds standard chat permissions. The attacker sends a crafted HTTP DELETE request to the poll endpoint substituting the numeric ID of another participant's draft. No user interaction from the victim is required. Attackers can script enumeration across sequential IDs to remove drafts in bulk.
// Security patch in lib/Controller/PollController.php
// Source: https://github.com/nextcloud/spreed/commit/bd68e80d1dea98d84c1d621c2c681238cf041725
if ($poll->getStatus() === Poll::STATUS_DRAFT) {
if (!$this->participant->hasModeratorPermissions(false)) {
// Only moderators can manage drafts
return new DataResponse(['error' => PollPropertyException::REASON_POLL], Http::STATUS_NOT_FOUND);
}
$this->pollService->deleteByPollId($poll->getId());
return new DataResponse(null, Http::STATUS_ACCEPTED);
}
The patch introduces an explicit hasModeratorPermissions(false) check before invoking the delete operation, returning HTTP 404 for unauthorized callers.
Detection Methods for CVE-2025-66556
Indicators of Compromise
- Unexpected HTTP DELETE requests against /ocs/v2.php/apps/spreed/api/v1/poll/ endpoints originating from non-moderator user accounts.
- Application log entries showing poll draft deletions performed by participants who did not author the drafts.
- Sequential or rapid enumeration patterns targeting numeric poll identifiers from a single session.
Detection Strategies
- Correlate poll draft deletion events with participant roles, flagging cases where the actor lacks moderator permissions on affected conversations.
- Baseline normal poll activity per conversation and alert on abnormal deletion volumes within short time windows.
- Inspect Nextcloud audit logs for spreed API calls that manipulate poll IDs outside the caller's authored records.
Monitoring Recommendations
- Enable verbose logging for the Nextcloud Talk (spreed) application and forward logs to a centralized SIEM.
- Track HTTP status responses on the poll API endpoints; a shift from 202 to 404 responses after patching confirms the authorization check is enforced.
- Monitor Nextcloud version telemetry across the estate to confirm all Talk deployments run 20.1.8, 21.1.2, or later.
How to Mitigate CVE-2025-66556
Immediate Actions Required
- Upgrade Nextcloud Talk to version 20.1.8 or 21.1.2 as soon as maintenance windows allow.
- Review conversation participant lists and remove untrusted accounts from sensitive conversations until patching is complete.
- Audit recent poll draft deletion activity through Nextcloud application logs to identify any unauthorized removals.
Patch Information
Nextcloud released fixed builds in Talk 20.1.8 and 21.1.2. The corrective commit bd68e80d1dea98d84c1d621c2c681238cf041725 adds a moderator permission check before executing poll draft deletions. Full details are documented in the Nextcloud GitHub Security Advisory GHSA-pr9f-vqgg-m2jh and the associated pull request #15532.
Workarounds
- Restrict chat permissions in sensitive conversations to trusted moderators only until the patch is deployed.
- Disable the poll feature in high-risk conversations by limiting participant roles that can interact with polls.
- Increase log retention and monitoring for the Talk application to enable rapid detection of exploitation attempts during the patch window.
# Update Nextcloud Talk via the occ command-line tool
sudo -u www-data php occ app:update spreed
# Verify installed version meets or exceeds the fixed release
sudo -u www-data php occ app:list | grep -A1 spreed
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.