Description
Denial-of-service vulnerability in M-Files Server versions before 26.5.16015.3 allows an authenticated admin user to cause the M-Files Server process to crash and fail to restart.
Published: 2026-08-05
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in M‑Files Server allows an authenticated administrator to trigger a crash of the server process. The crash is fatal because the process fails to restart automatically, leading to a loss of service availability. The weakness is classified as CWE‑1286, reflecting improper handling of admin input that results in denial of service.

Affected Systems

All installations of M‑Files Corporation’s M‑Files Server running a version older than 26.5.16015.3 are affected. The vulnerability exists in any pre‑26.5.16015.3 release.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium‑high severity. The EPSS score is not provided and the issue is not listed in CISA’s KEV catalog, suggesting that widespread exploitation has not been observed. Exploitation requires an authenticated admin user; it does not appear to be achievable unauthenticated or remote. Consequently the risk to organizations depends strongly on their administrator access management, but the potential impact of a sustained outage makes the vulnerability a priority for immediate patching.

Generated by OpenCVE AI on August 5, 2026 at 11:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued update that includes version 26.5.16015.3 or later to fix the issue.
  • Restrict administrative privileges to only essential users and enforce least‑privilege policies.
  • Monitor the server for unexpected crashes and configure automated restarts or a high‑availability arrangement to maintain uptime during a critical incident.

Generated by OpenCVE AI on August 5, 2026 at 11:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared M-files
M-files server
Vendors & Products M-files
M-files server

Wed, 05 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Description Denial-of-service vulnerability in M-Files Server versions before 26.5.16015.3 allows an authenticated admin user to cause the M-Files Server process to crash and fail to restart.
Title Denial-of-service vulnerability in M-Files Server
Weaknesses CWE-1286
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: M-Files Corporation

Published:

Updated: 2026-08-07T09:30:07.290Z

Reserved: 2026-01-14T07:33:57.497Z

Link: CVE-2026-0931

cve-icon Vulnrichment

Updated: 2026-08-05T13:02:39.117Z

cve-icon NVD

Status : Received

Published: 2026-08-05T10:17:26.860

Modified: 2026-08-05T13:20:34.177

Link: CVE-2026-0931

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T12:00:10Z

Weaknesses
  • CWE-1286

    Improper Validation of Syntactic Correctness of Input