CVE-2025-66558

LOW

Nextcloud Twofactor WebAuthn <1.4.2, <2.4.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

Nextcloud Twofactor WebAuthn is the WebAuthn Two-Factor Provider for Nextcloud. Prior to 1.4.2 and 2.4.1, a missing ownership check allowed an attack to take-away a 2FA webauthn device when correctly guessing a 80-128 character long random string of letters, numbers and symbols. The victim would then be prompted to register a new device on the next login. The attacker can not authenticate as the victim. This vulnerability is fixed in 1.4.2 and 2.4.1.

References (4)

Core 4

Scores

CVSS v3 3.1
EPSS 0.0003
EPSS Percentile 6.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (1)
nextcloud/two-factor_webauthn 1.0.0 - 1.4.2
Published Dec 05, 2025
Tracked Since Feb 18, 2026