CVE-2025-66558 | Nextcloud Twofactor WebAuthn up to 1.4.1/2.4.0 authorization (GHSA-fr8x-mvjg-wf9q)
A vulnerability was found in Nextcloud Twofactor WebAuthn up to 1.4.1/2.4.0. It has been classified as problematic. The affected element is an unknown function. This manipulation causes authorization bypass.
The identification of this vulnerability is CVE-2025-66558. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.