CVE-2025-47794
Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 29.0.13, 30.0.7, and 31.0.1 and Nextcloud Enterprise Server prior to 26.0.13.13, 27.1.11.13, 28.0.14.4, 29.0.13, 30.0.7, and 31.0.1, an attacker on a multi-user system may read temporary files from Nextcloud running with a different user account, or run a symlink attack. Nextcloud Server versions 29.0.13, 30.0.7, and 31.0.1 and Nextcloud Enterprise Server 26.0.13.13, 27.1.11.13, 28.0.14.4, 29.0.13, 30.0.7, and 31.0.1 fix the issue. No known workarounds are available.
- Affected products
- Nextcloud Enterprise Server, Nextcloud Server
- Nextcloud Nextcloud Server
- < 26.0.13.13, 27.1.11.13, 28.0.14.4, 29.0.13, 30.0.7, 31.0.1
- Fix
- Available
- CVSS 3.1
- 4.3 MEDIUM
- EPSS
- 0.4% (34th percentile)
- Weakness
- CWE-284
- NVD status
- Analyzed
- Published
- 2025-05-16
No indexed exploits for CVE-2025-47794 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2025-47794 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.