CVE-2025-3086: M-Files Server

High severity, CVSS 7.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Improper isolation of users in M-Files Server version before 25.3.14549 allows anonymous user to affect other anonymous users views and possibly cause a denial of service

Affected products

  • M-Files M-Files Server: before 25.3.14549 (fixed in 25.3.14549)

Published 2025-04-04. Last modified 2026-06-17.