# CVE-2025-3086

## Summary

- **CVE ID:** CVE-2025-3086
- **Severity:** MEDIUM
- **CVSS Score:** 6.3 (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L)
- **CWE:** CWE-653
- **Published:** Apr 4, 2025
- **Last Modified:** Mar 12, 2026

## Description

Improper isolation of users in M-Files Server version before 25.3.14549 allows anonymous user to affect other anonymous users views and possibly cause a denial of service

## Affected Products

- M-Files Corporation — M-Files Server (0)

## References

- [CNA](https://product.m-files.com/security-advisories/cve-2025-3086/)
- [CNA](https://empower.m-files.com/security-advisories/CVE-2025-3086)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.42%
- **EPSS Percentile:** 34.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._