CVE-2025-66558
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/12/2025
Last modified:
09/12/2025
Description
Nextcloud Twofactor WebAuthn is the WebAuthn Two-Factor Provider for Nextcloud. Prior to 1.4.2 and 2.4.1, a missing ownership check allowed an attack to take-away a 2FA webauthn device when correctly guessing a 80-128 character long random string of letters, numbers and symbols. The victim would then be prompted to register a new device on the next login. The attacker can not authenticate as the victim. This vulnerability is fixed in 1.4.2 and 2.4.1.
Impact
Base Score 3.x
3.10
Severity 3.x
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:nextcloud:two-factor_webauthn:*:*:*:*:*:*:*:* | 1.0.0 (including) | 1.4.2 (excluding) |
| cpe:2.3:a:nextcloud:two-factor_webauthn:*:*:*:*:*:*:*:* | 2.0.0 (including) | 2.4.1 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



