
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14267 is an incomplete removal of sensitive information before transfer vulnerability in M-Files Corporation M-Files Server, classified under CWE-212. It allows privileged network attackers to expose sensitive data during transfer operations where that data should have been removed beforehand. All M-Files Server versions before 25.12.15491.7 are affected. The vulnerability was published on December 19, 2025, with a patch released shortly after. It carries a CVSS v3.1 base score of 4.9 (Medium) and a CVSS v4.0 base score of 5.6 (Medium) (M-Files Advisory, Red Hat CVE).
The root cause is classified as CWE-212 (Improper Removal of Sensitive Information Before Storage or Transfer), specifically involving unintended temporary cached data being included in a structure-only copy intended to exclude it. The attack vector is network-based and requires high privileges, with no user interaction required under CVSS v3.1 conditions, though CVSS v4.0 notes active user interaction and specific attack requirements (AT:P). A technical write-up describes the flaw as unintended temporary cached data being included in a copy operation that was meant to transfer only structural data, thereby leaking sensitive content (M-Files Advisory, Infinitsec).
Successful exploitation results in a high confidentiality impact — sensitive information stored or cached in M-Files Server can be exposed to an attacker with high-privilege network access. There is no integrity or availability impact associated with this vulnerability. The exposure is limited to data leakage during specific transfer operations, with no evidence of lateral movement capability or system compromise beyond information disclosure (M-Files Advisory, ENISA EUVD).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure. The EPSS score is approximately 0.039%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires high privileges and specific environmental conditions, significantly limiting the attack surface (M-Files Advisory, Red Hat CVE).
Organizations should upgrade M-Files Server to version 25.12.15491.7 or later, which contains the fix for this vulnerability. As interim measures, restrict high-privilege account access to M-Files Server, implement network-level controls to limit exposure of the server, and monitor data transfer operations and access logs for suspicious activity by privileged users. No configuration-only workaround has been published by the vendor (M-Files Advisory).
Security news outlet SecurityOnline.info covered the vulnerability, framing it as an identity-related flaw allowing insiders to access sensitive data (SecurityOnline). The vulnerability received limited broader community attention, consistent with its medium severity rating and the requirement for high privileges to exploit. No notable researcher commentary or significant social media discussion beyond automated CVE tracking posts has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."