Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 09 Dec 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nextcloud two-factor Webauthn
|
|
| CPEs | cpe:2.3:a:nextcloud:two-factor_webauthn:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nextcloud two-factor Webauthn
|
Tue, 09 Dec 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nextcloud
Nextcloud twofactor Webauthn |
|
| Vendors & Products |
Nextcloud
Nextcloud twofactor Webauthn |
Fri, 05 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 05 Dec 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nextcloud Twofactor WebAuthn is the WebAuthn Two-Factor Provider for Nextcloud. Prior to 1.4.2 and 2.4.1, a missing ownership check allowed an attack to take-away a 2FA webauthn device when correctly guessing a 80-128 character long random string of letters, numbers and symbols. The victim would then be prompted to register a new device on the next login. The attacker can not authenticate as the victim. This vulnerability is fixed in 1.4.2 and 2.4.1. | |
| Title | Nextcloud Twofactor WebAuthn app was updated based on public key | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-12-05T18:35:53.477Z
Reserved: 2025-12-04T16:01:32.473Z
Link: CVE-2025-66558
Updated: 2025-12-05T18:35:45.357Z
Status : Analyzed
Published: 2025-12-05T18:15:59.140
Modified: 2025-12-09T16:44:58.910
Link: CVE-2025-66558
No data.
OpenCVE Enrichment
Updated: 2025-12-08T09:39:52Z