CVE-2023-6189: M-Files Server

Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.

Missing access permissions checks in the M-Files server before 23.11.13156.0 allow attackers to perform data write and export jobs using the M-Files API methods.

Affected products

  • M-Files M-Files Server: before 23.11.13156.0 (fixed in 23.11.13156.0)

Published 2023-11-22. Last modified 2026-06-17.