Vulnerability Details CVE-2026-0663
Denial-of-service vulnerability in M-Files Server versions before 26.1.15632.3 allows an authenticated attacker with vault administrator privileges to crash the M-Files Server process by calling a vulnerable API endpoint.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 28.0%
CVSS Severity
CVSS v3 Score 4.9
Products affected by CVE-2026-0663
-
cpe:2.3:a:m-files:m-files_server:-
-
cpe:2.3:a:m-files:m-files_server:22.11.12011.0
-
cpe:2.3:a:m-files:m-files_server:22.12.12140.3
-
cpe:2.3:a:m-files:m-files_server:22.2.11051.0
-
cpe:2.3:a:m-files:m-files_server:22.3.11237.3
-
cpe:2.3:a:m-files:m-files_server:22.6.11534.4
-
cpe:2.3:a:m-files:m-files_server:23.11.13168.6
-
cpe:2.3:a:m-files:m-files_server:23.12.13195.0
-
cpe:2.3:a:m-files:m-files_server:23.12.13205.0
-
cpe:2.3:a:m-files:m-files_server:23.2.12340.6
-
cpe:2.3:a:m-files:m-files_server:23.4.12455.0
-
cpe:2.3:a:m-files:m-files_server:23.4.12528.1
-
cpe:2.3:a:m-files:m-files_server:23.6.12695.3
-
cpe:2.3:a:m-files:m-files_server:23.8.12892.17
-
cpe:2.3:a:m-files:m-files_server:23.8.12892.23
-
cpe:2.3:a:m-files:m-files_server:23.8.12892.6
-
cpe:2.3:a:m-files:m-files_server:23.9
-
cpe:2.3:a:m-files:m-files_server:24.11.14245.5
-
cpe:2.3:a:m-files:m-files_server:24.2.13421.11
-
cpe:2.3:a:m-files:m-files_server:24.2.13421.15
-
cpe:2.3:a:m-files:m-files_server:24.2.13421.17
-
cpe:2.3:a:m-files:m-files_server:24.2.13421.8
-
cpe:2.3:a:m-files:m-files_server:24.4.13592
-
cpe:2.3:a:m-files:m-files_server:24.8.13981.0
-
cpe:2.3:a:m-files:m-files_server:24.8.13981.11
-
cpe:2.3:a:m-files:m-files_server:24.8.13981.13
-
cpe:2.3:a:m-files:m-files_server:24.8.13981.14
-
cpe:2.3:a:m-files:m-files_server:24.8.13981.16
-
cpe:2.3:a:m-files:m-files_server:24.8.13981.4
-
cpe:2.3:a:m-files:m-files_server:24.8.13981.8
-
cpe:2.3:a:m-files:m-files_server:24.9.14055.3
-
cpe:2.3:a:m-files:m-files_server:25.1.14445.5
-
cpe:2.3:a:m-files:m-files_server:25.11.15392.1
-
cpe:2.3:a:m-files:m-files_server:25.12
-
cpe:2.3:a:m-files:m-files_server:25.12.15491.7
-
cpe:2.3:a:m-files:m-files_server:25.12.15491.9
-
cpe:2.3:a:m-files:m-files_server:25.2.14524.13
-
cpe:2.3:a:m-files:m-files_server:25.2.14524.3
-
cpe:2.3:a:m-files:m-files_server:25.2.14524.9
-
cpe:2.3:a:m-files:m-files_server:25.3.14549
-
cpe:2.3:a:m-files:m-files_server:25.3.14681.7
-
cpe:2.3:a:m-files:m-files_server:25.6.14925.0
-
cpe:2.3:a:m-files:m-files_server:25.8.15085.13
-
cpe:2.3:a:m-files:m-files_server:25.8.15085.17