Denial-of-service condition in M-Files Server versions before 26.5.16015.0, before 26.2 LTS, and before 25.8 LTS SR3 allows an authenticated user to cause the MFserver process to crash
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 18 May 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 18 May 2026 12:00:00 +0000

Type Values Removed Values Added
Description Denial-of-service condition in M-Files Server versions before 26.5.16015.0, before 26.2 LTS, and before 25.8 LTS SR3 allows an authenticated user to cause the MFserver process to crash
Title Denial of service vulnerability in M-Files Server
First Time appeared M-files Corporation
M-files Corporation m-files Server
Weaknesses CWE-1286
CPEs cpe:2.3:a:m-files_corporation:m-files_server:*:*:*:*:*:*:*:*
Vendors & Products M-files Corporation
M-files Corporation m-files Server
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: M-Files Corporation

Published:

Updated: 2026-05-18T12:40:39.485Z

Reserved: 2026-01-15T10:18:50.486Z

Link: CVE-2026-0983

cve-icon Vulnrichment

Updated: 2026-05-18T12:40:34.870Z

cve-icon NVD

Status : Received

Published: 2026-05-18T12:16:16.230

Modified: 2026-05-18T12:16:16.230

Link: CVE-2026-0983

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-18T13:30:06Z

Weaknesses