CVE-2026-0663
M-Files Server vulnerability analysis and mitigation

Overview

CVE-2026-0663 is a denial-of-service (DoS) vulnerability in M-Files Server that allows an authenticated attacker with vault administrator privileges to crash the M-Files Server process by calling a vulnerable API endpoint. It affects all M-Files Server versions before 26.1.15632.3. The CVE was published on January 21, 2026, by M-Files Corporation, with NVD initial analysis completed on February 2, 2026. It carries a CVSS v3.1 base score of 4.9 (Medium) and a CVSS v4.0 base score of 6.9 (Medium) (M-Files Advisory, M-Files Empower).

Technical details

The root cause is classified as CWE-1286 (Improper Validation of Syntactic Correctness of Input), meaning the server fails to properly validate input passed to a specific API endpoint before processing it. An authenticated attacker with vault administrator privileges can send a specially crafted request to this vulnerable endpoint, causing the M-Files Server process to crash. The attack vector is network-based, requires no user interaction, and has low attack complexity, but does require high privileges (vault administrator access) as a precondition. No public proof-of-concept or detailed technical write-up has been identified at this time (M-Files Advisory).

Impact

Successful exploitation results in a denial-of-service condition, crashing the M-Files Server process and making the server unavailable to legitimate users. This causes service disruption for all M-Files deployments relying on the affected server instance. There is no impact on data confidentiality or integrity — the vulnerability is limited to availability (M-Files Advisory).

Exploitability

There is no evidence of a public proof-of-concept exploit or active in-the-wild exploitation at this time. The vulnerability requires the attacker to already possess vault administrator privileges, significantly limiting the attack surface. The EPSS score is approximately 0.078%, reflecting a low probability of exploitation in the near term. CVE-2026-0663 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (M-Files Advisory).

Mitigation and workarounds

M-Files has released a patch in M-Files Server version 26.1.15632.3, which resolves this vulnerability. Organizations should upgrade to version 26.1.15632.3 or later as the primary remediation step. As a complementary measure, vault administrator privileges should be restricted to trusted accounts only, and network access controls should be implemented to limit exposure of M-Files Server API endpoints to authorized users and systems (M-Files Advisory, M-Files Empower).

Additional resources


SourceThis report was generated using AI

Related M-Files Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-13008HIGH8.6
  • M-Files Server logoM-Files Server
  • cpe:2.3:a:m-files:m-files_server
NoYesDec 19, 2025
CVE-2026-0931MEDIUM6.9
  • M-Files Server logoM-Files Server
  • cpe:2.3:a:m-files:m-files_server
NoYesAug 05, 2026
CVE-2026-0932MEDIUM6.9
  • M-Files Server logoM-Files Server
  • cpe:2.3:a:m-files:m-files_server
NoYesApr 01, 2026
CVE-2026-0663MEDIUM6.9
  • M-Files Server logoM-Files Server
  • cpe:2.3:a:m-files:m-files_server
NoYesJan 21, 2026
CVE-2025-14267MEDIUM5.6
  • M-Files Server logoM-Files Server
  • cpe:2.3:a:m-files:m-files_server
NoYesDec 19, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management