CVE-2023-6912: M-Files Server
Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.
Lack of protection against brute force attacks in M-Files Server before 23.12.13205.0 allows an attacker unlimited authentication attempts, potentially compromising targeted M-Files user accounts by guessing passwords.
Affected products
- M-Files M-Files Server: before 23.12.13205.0 (fixed in 23.12.13205.0)
Published 2023-12-20. Last modified 2026-06-17.