CVE-2025-14318
M-Files Server vulnerability analysis and mitigation

Overview

CVE-2025-14318 is an improper access control vulnerability in M-Files Server that allows authenticated users to bypass the Print and Download Prevention module and download files via M-Files Web using the Web Companion. It affects M-Files Server versions before 25.12.15491.7. The vulnerability was published on December 18, 2025, and assigned by M-Files Corporation. It carries a CVSS v3.1 base score of 4.3 (Medium) and a CVSS v4.0 base score of 5.3 (Medium) (M-Files Advisory, Red Hat CVE).

Technical details

The root cause is classified as CWE-863 (Incorrect Authorization) — the server fails to properly enforce access checks when users request file downloads through M-Files Web via the Web Companion component, even when the Print and Download Prevention module is explicitly enabled. An authenticated, low-privileged user can exploit this over the network without any user interaction or elevated privileges, simply by using the Web Companion interface to initiate a download that should be blocked by the DLP module. No special configuration or complex attack chain is required beyond having a valid user account (M-Files Advisory).

Impact

Successful exploitation allows authenticated users with low privileges to circumvent the Print and Download Prevention security control and exfiltrate files from M-Files Web that should be restricted. The primary impact is a confidentiality breach — sensitive documents stored in M-Files can be downloaded without authorization. There is no integrity or availability impact, and the scope is limited to the affected M-Files Server instance (M-Files Advisory, Red Hat CVE).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.038%, reflecting a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires a valid (low-privileged) user account, which limits the attack surface to authenticated insiders or compromised credentials (M-Files Advisory).

Mitigation and workarounds

M-Files has released a patch in M-Files Server version 25.12.15491.7 and later, which corrects the improper access checks. Organizations should upgrade to this version or newer as the primary remediation. As an interim measure until patching is complete, administrators should review and restrict user access permissions to limit download capabilities, and monitor Web Companion usage logs for unauthorized file download activity (M-Files Advisory).

Additional resources


SourceThis report was generated using AI

Related M-Files Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-13008HIGH8.6
  • M-Files Server logoM-Files Server
  • cpe:2.3:a:m-files:m-files_server
NoYesDec 19, 2025
CVE-2026-0931MEDIUM6.9
  • M-Files Server logoM-Files Server
  • cpe:2.3:a:m-files:m-files_server
NoYesAug 05, 2026
CVE-2026-0932MEDIUM6.9
  • M-Files Server logoM-Files Server
  • cpe:2.3:a:m-files:m-files_server
NoYesApr 01, 2026
CVE-2026-0663MEDIUM6.9
  • M-Files Server logoM-Files Server
  • cpe:2.3:a:m-files:m-files_server
NoYesJan 21, 2026
CVE-2025-14267MEDIUM5.6
  • M-Files Server logoM-Files Server
  • cpe:2.3:a:m-files:m-files_server
NoYesDec 19, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management