7.1
CVE-2026-0983
- EPSS 0.23%
- Veröffentlicht 18.05.2026 11:05:29
- Zuletzt bearbeitet 18.05.2026 19:32:38
- Quelle security@m-files.com
- CVE-Watchlists
- Unerledigt
Denial of service vulnerability in M-Files Server
Denial-of-service condition in M-Files Server versions before 26.5.16015.0, before 26.2 LTS, and before 25.8 LTS SR3 allows an authenticated user to cause the MFserver process to crash
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerM-Files Corporation
≫
Produkt
M-Files Server
Default Statusunaffected
Version
0
Version <
26.5.16015.0
Status
affected
Version
LTS 25.8.15085.13
Version <
LTS 25.8.15085.24
Status
affected
Version
LTS 26.2.15718.8
Version <
LTS 26.2.15718.10
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.23% | 0.13 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@m-files.com | 7.1 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-1286 Improper Validation of Syntactic Correctness of Input
The product receives input that is expected to be well-formed - i.e., to comply with a certain syntax - but it does not validate or incorrectly validates that the input complies with the syntax.
https://empower.m-files.com/security-advisories/CVE-2026-0983