CVE-2025-13008
M-Files Server vulnerability analysis and mitigation

Overview

CVE-2025-13008 is an information disclosure vulnerability in M-Files Server that allows an authenticated attacker using M-Files Web to capture session tokens of other active users. It affects M-Files Server versions before 25.12.15491.7, 25.8 LTS SR3, 25.2 LTS SR3, and 24.8 LTS SR5. The vulnerability was published on December 19, 2025, and assigned by M-Files Corporation. It carries a CVSS v4.0 base score of 8.6 (High) (M-Files Advisory, ENISA EUVD).

Technical details

The vulnerability is classified under CWE-359 (Exposure of Private Personal Information to an Unauthorized Actor), indicating that the M-Files Web interface improperly exposes session tokens belonging to other active users to authenticated low-privilege users. The attack vector is network-based, requires low privileges, and involves passive user interaction, suggesting the attacker may need to observe or intercept session data through the web interface. No specific technical write-up or proof-of-concept code has been publicly disclosed at this time (M-Files Advisory, ENISA EUVD).

Impact

Successful exploitation allows a low-privilege authenticated attacker to intercept and steal active session tokens of other users on the M-Files Server, potentially enabling full account takeover of any active user — including administrators. This could lead to unauthorized access to sensitive documents and data managed within M-Files, identity theft, data breaches, and further lateral movement within the M-Files Server environment (M-Files Advisory, Security Online).

Exploitability

There is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation as of the time of disclosure. The EPSS score is approximately 0.042%, reflecting a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (M-Files Advisory, CCB Belgium Advisory).

Mitigation and workarounds

M-Files has released patched versions addressing this vulnerability: 25.12.15491.7, 25.8 LTS SR3, 25.2 LTS SR3, and 24.8 LTS SR5. Organizations should upgrade to one of these versions immediately. As additional hardening measures, administrators should implement multi-factor authentication, monitor for anomalous authentication activity, limit user privileges, and consider regularly rotating session tokens until patching is complete (M-Files Advisory, CCB Belgium Advisory).

Community reactions

The Belgium Centre for Cybersecurity (CCB) issued an advisory urging organizations to patch immediately, classifying the vulnerability as high severity (CCB Belgium Advisory). The Isle of Man's Cyber Security Centre also published a vulnerability notice covering this flaw (CSC IoM). The vulnerability received coverage from multiple cybersecurity news outlets including GBHackers, CyberSecurityNews, and The Hacker News' weekly recap, highlighting the session hijacking risk for enterprise document management environments (GBHackers, CyberSecurityNews, The Hacker News).

Additional resources


SourceThis report was generated using AI

Related M-Files Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-13008HIGH8.6
  • M-Files Server logoM-Files Server
  • cpe:2.3:a:m-files:m-files_server
NoYesDec 19, 2025
CVE-2026-0931MEDIUM6.9
  • M-Files Server logoM-Files Server
  • cpe:2.3:a:m-files:m-files_server
NoYesAug 05, 2026
CVE-2026-0932MEDIUM6.9
  • M-Files Server logoM-Files Server
  • cpe:2.3:a:m-files:m-files_server
NoYesApr 01, 2026
CVE-2026-0663MEDIUM6.9
  • M-Files Server logoM-Files Server
  • cpe:2.3:a:m-files:m-files_server
NoYesJan 21, 2026
CVE-2025-14267MEDIUM5.6
  • M-Files Server logoM-Files Server
  • cpe:2.3:a:m-files:m-files_server
NoYesDec 19, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management