CVE-2026-18372
Deferred Deferred - Pending Action

CSS Injection in M-Files Web Before 26.8.16330.2

Vulnerability report for CVE-2026-18372, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-31

Assigner: M-Files Corporation

Description

CSS injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated vault administrator to inject arbitrary CSS, affecting the web user interface displayed to other vault users.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-31
Generated
2026-09-08
AI Q&A
2026-08-19
EPSS Evaluated
2026-09-07
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
m-files m-files_web 26.8.16330.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a CSS injection vulnerability in M-Files Web before version 26.8.16330.2. An authenticated vault administrator can inject arbitrary CSS code, which affects the web user interface seen by other users.

Detection Guidance

Detecting CSS injection vulnerabilities typically requires manual review of web application inputs and outputs. Check M-Files Web logs for suspicious CSS payloads in requests from vault administrators. Inspect rendered HTML output for unexpected style tags or inline CSS in user interfaces. No specific commands are provided for this CVE.

Impact Analysis

An attacker with admin access could modify the UI for other users, potentially leading to phishing attacks, misleading information display, or unauthorized data exposure through crafted styles.

Compliance Impact

This vulnerability allows a vault administrator to inject arbitrary CSS into the web interface, which could manipulate how data is displayed to other users. This may lead to misrepresentation of sensitive information, potentially violating data integrity and confidentiality requirements under standards like GDPR and HIPAA.

Mitigation Strategies

Update M-Files Web to version 26.8.16330.2 or later to address the CSS injection vulnerability. Restrict vault administrator privileges to only those necessary for their roles. Monitor web interface behavior for unusual CSS changes after updates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18372. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart