Improper access checks in M-Files Server before 25.12 allows users to download files through M-Files Web using Web Companion despite Print and Download Prevention module being enabled.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
Update to the latest version.
Workaround
No workaround available on affected versions.
References
History
Thu, 18 Dec 2025 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper access checks in M-Files Server before 25.12 allows users to download files through M-Files Web using Web Companion despite Print and Download Prevention module being enabled. | |
| Title | Improper access validation in M-Files Server | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: M-Files Corporation
Published:
Updated: 2025-12-18T07:32:34.230Z
Reserved: 2025-12-09T10:22:36.277Z
Link: CVE-2025-14318
No data.
Status : Received
Published: 2025-12-18T08:15:49.653
Modified: 2025-12-18T08:15:49.653
Link: CVE-2025-14318
No data.
OpenCVE Enrichment
No data.
Weaknesses