
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14318 is an improper access control vulnerability in M-Files Server that allows authenticated users to bypass the Print and Download Prevention module and download files via M-Files Web using the Web Companion. It affects M-Files Server versions before 25.12.15491.7. The vulnerability was published on December 18, 2025, and assigned by M-Files Corporation. It carries a CVSS v3.1 base score of 4.3 (Medium) and a CVSS v4.0 base score of 5.3 (Medium) (M-Files Advisory, Red Hat CVE).
The root cause is classified as CWE-863 (Incorrect Authorization) — the server fails to properly enforce access checks when users request file downloads through M-Files Web via the Web Companion component, even when the Print and Download Prevention module is explicitly enabled. An authenticated, low-privileged user can exploit this over the network without any user interaction or elevated privileges, simply by using the Web Companion interface to initiate a download that should be blocked by the DLP module. No special configuration or complex attack chain is required beyond having a valid user account (M-Files Advisory).
Successful exploitation allows authenticated users with low privileges to circumvent the Print and Download Prevention security control and exfiltrate files from M-Files Web that should be restricted. The primary impact is a confidentiality breach — sensitive documents stored in M-Files can be downloaded without authorization. There is no integrity or availability impact, and the scope is limited to the affected M-Files Server instance (M-Files Advisory, Red Hat CVE).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.038%, reflecting a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires a valid (low-privileged) user account, which limits the attack surface to authenticated insiders or compromised credentials (M-Files Advisory).
M-Files has released a patch in M-Files Server version 25.12.15491.7 and later, which corrects the improper access checks. Organizations should upgrade to this version or newer as the primary remediation. As an interim measure until patching is complete, administrators should review and restrict user access permissions to limit download capabilities, and monitor Web Companion usage logs for unauthorized file download activity (M-Files Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."