CVE-2026-18372: M-Files Corporation M-Files Web

Medium severity, CVSS 4.8. EPSS: 0.4% chance of exploitation in the next 30 days.

CSS injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated vault administrator to inject arbitrary CSS, affecting the web user interface displayed to other vault users.

Affected products

Published 2026-08-19. Last modified 2026-08-31.