CVE-2022-4861: M-Files Client

Medium severity, CVSS 4.9. EPSS: 0.6% chance of exploitation in the next 30 days.

Incorrect implementation in authentication protocol in M-Files Client before 22.5.11356.0 allows high privileged user to get other users tokens to another resource.

Affected products

  • M-Files M-Files Client: before 22.5.11356.0 (fixed in 22.5.11356.0)

Published 2022-12-30. Last modified 2026-06-17.