CVE-2022-47634: Isode M-Link

High severity, CVSS 8.1. EPSS: 0.5% chance of exploitation in the next 30 days.

M-Link Archive Server in Isode M-Link R16.2v1 through R17.0 before R17.0v24 allows non-administrative users to access and manipulate archive data via certain HTTP endpoints, aka LINK-2867.

Affected products

  • Isode M-Link: from r16.2v1, before r17.0v24 (fixed in r17.0v24)

Published 2023-01-01. Last modified 2026-06-17.