Impact
A flaw in M‑Files Server allows an authenticated administrator to trigger a crash of the server process. The crash is fatal because the process fails to restart automatically, leading to a loss of service availability. The weakness is classified as CWE‑1286, reflecting improper handling of admin input that results in denial of service.
Affected Systems
All installations of M‑Files Corporation’s M‑Files Server running a version older than 26.5.16015.3 are affected. The vulnerability exists in any pre‑26.5.16015.3 release.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium‑high severity. The EPSS score is not provided and the issue is not listed in CISA’s KEV catalog, suggesting that widespread exploitation has not been observed. Exploitation requires an authenticated admin user; it does not appear to be achievable unauthenticated or remote. Consequently the risk to organizations depends strongly on their administrator access management, but the potential impact of a sustained outage makes the vulnerability a priority for immediate patching.
OpenCVE Enrichment