Back to Database
Status published
Medium
CVE-2024-52511
Nextcloud Tables has an Authorization Bypass Through User-Controlled Key in Tables
Vulnerability Description
Nextcloud Tables allows users to to create tables with individual columns. By directly specifying the ID of a table or view, a malicious user could blindly insert new rows into tables they have no access to. It is recommended that the Nextcloud Tables is upgraded to 0.8.0.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-52511
Credits & Attribution
No credits recorded in the NVD database.
References
More from nextcloud
View All →CVE-2025-66558
Nextcloud Twofactor WebAuthn app was updated based on public key
Low
3.1
CVE-2025-66557
Nextcloud Deck app allowed user with "Can share" permission to modify permissions of other non-owners
Medium
5.4
CVE-2025-66556
Nextcloud talk allows participants to blindly delete poll drafts of other users by ID
Low
3.5
CVE-2025-66554
Nextcloud Contacts vulnerable to Stored XSS in contacts app via organisation and title field
Low
3.5
CVE-2025-66553
Nextcloud Tables app allowed users to view columns metadata information of any table
Medium
4.3
Affected Vendor
nextcloud
View all reports →Affected Software
security-advisories
Vulnerable Versions:
>= 0.6.0, < 0.8.0
Timeline
Official Publish:
November 15th, 2024
Last Modified:
November 15th, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N