
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0663 is a denial-of-service (DoS) vulnerability in M-Files Server that allows an authenticated attacker with vault administrator privileges to crash the M-Files Server process by calling a vulnerable API endpoint. It affects all M-Files Server versions before 26.1.15632.3. The CVE was published on January 21, 2026, by M-Files Corporation, with NVD initial analysis completed on February 2, 2026. It carries a CVSS v3.1 base score of 4.9 (Medium) and a CVSS v4.0 base score of 6.9 (Medium) (M-Files Advisory, M-Files Empower).
The root cause is classified as CWE-1286 (Improper Validation of Syntactic Correctness of Input), meaning the server fails to properly validate input passed to a specific API endpoint before processing it. An authenticated attacker with vault administrator privileges can send a specially crafted request to this vulnerable endpoint, causing the M-Files Server process to crash. The attack vector is network-based, requires no user interaction, and has low attack complexity, but does require high privileges (vault administrator access) as a precondition. No public proof-of-concept or detailed technical write-up has been identified at this time (M-Files Advisory).
Successful exploitation results in a denial-of-service condition, crashing the M-Files Server process and making the server unavailable to legitimate users. This causes service disruption for all M-Files deployments relying on the affected server instance. There is no impact on data confidentiality or integrity — the vulnerability is limited to availability (M-Files Advisory).
There is no evidence of a public proof-of-concept exploit or active in-the-wild exploitation at this time. The vulnerability requires the attacker to already possess vault administrator privileges, significantly limiting the attack surface. The EPSS score is approximately 0.078%, reflecting a low probability of exploitation in the near term. CVE-2026-0663 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (M-Files Advisory).
M-Files has released a patch in M-Files Server version 26.1.15632.3, which resolves this vulnerability. Organizations should upgrade to version 26.1.15632.3 or later as the primary remediation step. As a complementary measure, vault administrator privileges should be restricted to trusted accounts only, and network access controls should be implemented to limit exposure of M-Files Server API endpoints to authorized users and systems (M-Files Advisory, M-Files Empower).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."