CVE-2026-0931
Received Received - Intake

Denial-of-Service in M-Files Server Before 26.5.16015.3

Vulnerability report for CVE-2026-0931, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: M-Files Corporation

Description

Denial-of-service vulnerability in M-Files Server versions beforeΒ 26.5.16015.3 allows an authenticated admin user to cause the M-Files Server process to crash and fail to restart.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
m-files m-files_server 26.5.16015.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1286 The product receives input that is expected to be well-formed - i.e., to comply with a certain syntax - but it does not validate or incorrectly validates that the input complies with the syntax.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a denial-of-service vulnerability in M-Files Server versions before 26.5.16015.3. An authenticated admin user can exploit it to crash the M-Files Server process, causing it to fail to restart.

Detection Guidance

Monitor M-Files Server process crashes or failures to restart. Check server logs for admin user actions causing crashes. No specific commands provided in the context.

Impact Analysis

If exploited, this vulnerability could disrupt M-Files Server operations, leading to service unavailability for users relying on the system. It requires an authenticated admin account, limiting the risk to authorized users.

Compliance Impact

The vulnerability allows an authenticated admin user to crash the M-Files Server, causing a denial-of-service condition. This could disrupt access to critical data, potentially leading to violations of availability requirements in GDPR and HIPAA, which mandate timely access to personal health or user data.

Mitigation Strategies

Upgrade M-Files Server to version 26.5.16015.3 or later to address the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-0931. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart