CVE-2026-0932: M-Files Server

High severity, CVSS 7.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Blind server-side request forgery (SSRF) vulnerability in legacy connection methods of document co-authoring features in M-Files Server before 26.3 allow an unauthenticated attacker to cause the server to send HTTP GET requests to arbitrary URLs.

Affected products

  • M-Files M-Files Server: before 26.3.15818.5 (fixed in 26.3.15818.5)

Published 2026-04-01. Last modified 2026-06-17.