CVE-2025-66556: Nextcloud Talk

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Nextcloud talk is a video & audio conferencing app for Nextcloud. Prior to 20.1.8 and 21.1.2, a participant with chat permissions was able to delete poll drafts of other participants within the conversation based on their numeric ID. This vulnerability is fixed in 20.1.8 and 21.1.2.

Affected products

  • Nextcloud Talk: from 20.0.0, before 20.1.8 (fixed in 20.1.8); from 21.0.0, before 21.1.2 (fixed in 21.1.2)

Published 2025-12-05. Last modified 2026-06-17.