CVE-2024-10127: M-Files Server
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Authentication bypass condition in LDAP authentication in M-Files server versions before 24.11 supported usage of OpenLDAP configurations that allowed user authentication without a password when the LDAP server itself had the vulnerable configuration.
Affected products
- M-Files M-Files Server: before 24.8.13981.13 (fixed in 24.8.13981.13); before 24.11 (fixed in 24.11)
Published 2024-11-20. Last modified 2026-06-17.