Home

Description

Denial-of-service condition in M-Files Server versions before 25.11.15392.1, before 25.2 LTS SR2 and before 25.8 LTS SR2 allows an authenticated user to cause the MFserver process to crash.

PUBLISHED Reserved 2025-10-13 | Published 2025-11-17 | Updated 2025-11-17 | Assigner M-Files Corporation




HIGH: 7.1CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Problem types

CWE-400 Uncontrolled Resource Consumption

Product status

Default status
unaffected

Any version before 25.11.15392.1
affected

25.2.14524.13
unaffected

25.8.15085.17
unaffected

References

product.m-files.com/security-advisories/cve-2025-11681/

cve.org (CVE-2025-11681)

nvd.nist.gov (CVE-2025-11681)

Download JSON