Junglewise Threat Intelligence

CVE-2026-0983: M-Files Server denial of service in MFserver process

CVE-2026-0983 · Severity: info · CVSS 7.1 · Published 2026-05-18

Executive brief

A vulnerability in M-Files Server, a document management platform, allows a logged-in user to crash the server software. This results in a denial-of-service condition, preventing all users from accessing or managing documents until the service is restored. While it does not allow for data theft, it can significantly disrupt business operations and document workflows.

Technical details

A denial-of-service (DoS) vulnerability exists in M-Files Server due to improper validation of syntactic correctness of input (CWE-1286). An authenticated attacker with network access to the server can provide specially crafted input that causes the MFserver process to crash. The vulnerability affects versions prior to 26.5.16015.0, as well as older LTS branches (26.2 and 25.8). Successful exploitation results in a complete loss of availability for the M-Files service. Patches are available in version 26.5.16015.0 and the respective LTS service releases.

Affected products

  • M-Files Corporation M-Files Server before 26.5.16015.0, before 26.2 LTS, before 25.8 LTS SR3

Timeline

  • 2026-05-18: disclosed
  • 2026-05-18: advisory

References