CVE-2022-4264: M-Files

Medium severity, CVSS 4.3. EPSS: 0.6% chance of exploitation in the next 30 days.

Incorrect Privilege Assignment in M-Files Web (Classic) in M-Files before 22.8.11691.0 allows low privilege user to change some configuration.

Affected products

  • M-Files M-Files: before 22.8.11691.0 (fixed in 22.8.11691.0)

Published 2022-12-09. Last modified 2026-06-17.