CVE-2026-0663
Denial-of-service vulnerability in M-Files Server versions before 26.1.15632.3 allows an authenticated attacker with vault administrator privileges to crash the M-Files Server process by calling a vulnerable API endpoint.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.39%
- CWE
- CWE-1286
- Published
- 2026-01-21
- Last modified
- 2026-03-12
Affected products
- M-Files Corporation M-Files Server
Weakness type
Related vulnerabilities
- CVE-2026-83611 — xmldom: Parser silently accepts a not-well-formed end tag whose name is followed by a line break and trailing content
- CVE-2026-72916 — Mastodon: SSRF Protection Bypass via IPv4-compatible IPv6 Addresses
- CVE-2026-0931 — Denial-of-service vulnerability in M-Files Server
- CVE-2026-25292 — Improper Validation of Syntactic Correctness of Input in Automotive Linux OS
- CVE-2026-57026 — Junos OS: MX Series with SPC3, SRX Series: Processing of a specifically malformed SIP invite causes a flowd crash
- CVE-2026-55767 — Guzzle: Dot-Only Cookie Domains Match All Hosts in guzzlehttp/guzzle
- CVE-2026-50131 — Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges
- CVE-2025-8873 — Arista EOS Dataplane Denial of Service via Malformed IPsec Packet