Nextcloud talk is a video & audio conferencing app for Nextcloud. Prior to 20.1.8 and 21.1.2, a participant with chat permissions was able to delete poll drafts of other participants within the conversation based on their numeric ID. This vulnerability is fixed in 20.1.8 and 21.1.2.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 05 Dec 2025 18:15:00 +0000

Type Values Removed Values Added
Description Nextcloud talk is a video & audio conferencing app for Nextcloud. Prior to 20.1.8 and 21.1.2, a participant with chat permissions was able to delete poll drafts of other participants within the conversation based on their numeric ID. This vulnerability is fixed in 20.1.8 and 21.1.2.
Title Nextcloud talk allows participants to blindly delete poll drafts of other users by ID
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-12-05T18:09:34.326Z

Reserved: 2025-12-04T16:01:32.472Z

Link: CVE-2025-66556

cve-icon Vulnrichment

Updated: 2025-12-05T18:09:05.662Z

cve-icon NVD

Status : Received

Published: 2025-12-05T18:15:58.803

Modified: 2025-12-05T18:15:58.803

Link: CVE-2025-66556

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses