Description
Denial-of-service condition in M-Files Server versions before 26.5.16015.0, before 26.2 LTS, and before 25.8 LTS SR3 allows an authenticated user to cause the MFserver process to crash
Published: 2026-05-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 18 May 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 18 May 2026 12:00:00 +0000

Type Values Removed Values Added
Description Denial-of-service condition in M-Files Server versions before 26.5.16015.0, before 26.2 LTS, and before 25.8 LTS SR3 allows an authenticated user to cause the MFserver process to crash
Title Denial of service vulnerability in M-Files Server
First Time appeared M-files Corporation
M-files Corporation m-files Server
Weaknesses CWE-1286
CPEs cpe:2.3:a:m-files_corporation:m-files_server:*:*:*:*:*:*:*:*
Vendors & Products M-files Corporation
M-files Corporation m-files Server
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

M-files Corporation M-files Server
cve-icon MITRE

Status: PUBLISHED

Assigner: M-Files Corporation

Published:

Updated: 2026-05-18T12:40:39.485Z

Reserved: 2026-01-15T10:18:50.486Z

Link: CVE-2026-0983

cve-icon Vulnrichment

Updated: 2026-05-18T12:40:34.870Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-05-18T12:16:16.230

Modified: 2026-06-17T10:11:43.717

Link: CVE-2026-0983

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-18T14:30:05Z

Weaknesses