CVE-2024-6789: M-Files Server

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

A path traversal issue in API endpoint in M-Files Server before version 24.8.13981.0 and LTS 24.2.13421.15 SR2 and LTS 23.8.12892.0 SR6 allows authenticated user to read files

Affected products

  • M-Files M-Files Server: before 24.2.13421.15 (fixed in 24.2.13421.15); before 24.8.13981.0 (fixed in 24.8.13981.0)

Published 2024-08-27. Last modified 2026-06-17.