Home

Description

Improper isolation of users in M-Files Server version before 25.3.14549 allows anonymous user to affect other anonymous users views and possibly cause a denial of service

PUBLISHED Reserved 2025-04-01 | Published 2025-04-04 | Updated 2026-02-23 | Assigner M-Files Corporation




MEDIUM: 6.3CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L

Problem types

CWE-653

Product status

Default status
unaffected

Any version before 25.3.14549
affected

References

product.m-files.com/security-advisories/cve-2025-3086/ vendor-advisory

empower.m-files.com/security-advisories/CVE-2025-3086 vendor-advisory

cve.org (CVE-2025-3086)

nvd.nist.gov (CVE-2025-3086)

Download JSON