CVE-2026-18371
Deferred Deferred - Pending Action

HTML Injection in M-Files Web Before 26.8.16330.2

Vulnerability report for CVE-2026-18371, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-31

Assigner: M-Files Corporation

Description

HTML injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated attacker to affect web user interface contents displayed to other users.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-31
Generated
2026-09-08
AI Q&A
2026-08-19
EPSS Evaluated
2026-09-07
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
m-files m-files_web 26.8.16330.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an HTML injection vulnerability in M-Files Web before version 26.8.16330.2. An authenticated attacker can inject malicious HTML code into the web interface, which is then displayed to other users. This could allow the attacker to manipulate what other users see or interact with in the application.

Detection Guidance

This vulnerability involves HTML injection in M-Files Web before version 26.8.16330.2. To detect it, inspect web traffic for suspicious HTML content or unauthorized script execution in user interfaces. Check M-Files Web logs for unusual requests or responses containing injected HTML. Verify if the installed version is below 26.8.16330.2.

Impact Analysis

If you use M-Files Web before version 26.8.16330.2, an attacker with access could alter your user interface, potentially tricking you into performing unintended actions or disclosing sensitive information. This could lead to data breaches or unauthorized access to your documents.

Compliance Impact

This vulnerability could lead to unauthorized data exposure or manipulation, which may violate GDPR (data protection) or HIPAA (healthcare data privacy) requirements. Organizations using affected versions may face compliance violations, fines, or reputational damage if exploited.

Mitigation Strategies

Immediately update M-Files Web to version 26.8.16330.2 or later to patch the HTML injection flaw. Restrict user permissions to minimize potential impact. Monitor network traffic for signs of exploitation. Consider disabling affected web interfaces temporarily if an update is not immediately feasible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18371. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart