Home
MEDIUM: 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:NDefault status
unaffected
Any version before 26.3.15818.5
affected
Description
Blind server-side request forgery (SSRF) vulnerability in legacy connection methods of document co-authoring features in M-Files Server before 26.3 allow an unauthenticated attacker to cause the server to send HTTP GET requests to arbitrary URLs.
Problem types
CWE-918 Server-Side request forgery (SSRF)
Product status
Any version before 26.3.15818.5
Credits
Sina Kheirkhah (SinSinology) of watchTowr (watchTowrcyber)
References
empower.m-files.com/security-advisories/CVE-2026-0932
product.m-files.com/security-advisories/cve-2026-0932/