CVE-2023-6239: M-Files Server
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Under rare conditions, the effective permissions of an object might be incorrectly calculated if the object has a specific configuration of metadata-driven permissions in M-Files Server versions 23.9, 23.10, and 23.11 before 23.11.13168.7, potentially enabling unauthorized access to the object.
Affected products
- M-Files M-Files Server: from 23.11, before 23.11.13168.7 (fixed in 23.11.13168.7); version 23.9 only; version 23.10 only
Published 2023-11-28. Last modified 2026-06-17.