CVE-2025-0619: M-Files Server

Medium severity, CVSS 4.9. EPSS: 0.4% chance of exploitation in the next 30 days.

Unsafe password recovery from configuration in M-Files Server before 25.1 allows a highly privileged user to recover external connector passwords

Affected products

  • M-Files M-Files Server: before 25.1.14445.5 (fixed in 25.1.14445.5)

Published 2025-01-23. Last modified 2026-06-17.