
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0932 is a blind Server-Side Request Forgery (SSRF) vulnerability in M-Files Server affecting legacy connection methods used by document co-authoring features. An unauthenticated remote attacker can exploit this flaw to cause the server to issue arbitrary HTTP GET requests to attacker-controlled URLs. All M-Files Server versions before 26.3.15818.5 are affected. The vulnerability was published on April 1, 2026, with a CVSS v3.1 score of 7.3 (High) and a CVSS v4.0 score of 6.9 (Medium) (GitHub Advisory, M-Files Advisory).
The vulnerability is classified as CWE-918 (Server-Side Request Forgery), rooted in insufficient validation of URLs or request destinations within legacy connection methods of M-Files Server's document co-authoring functionality. An unauthenticated attacker can craft requests that cause the server to initiate outbound HTTP GET requests to arbitrary internal or external URLs without the server verifying the legitimacy of the destination. Because the SSRF is "blind," the attacker does not receive direct response content from the target URL, but can still infer information through timing or side-channel effects. No authentication or user interaction is required, and attack complexity is low (GitHub Advisory, M-Files Advisory).
Successful exploitation allows an unauthenticated attacker to leverage the M-Files Server as a proxy to probe internal network services, perform reconnaissance of internal infrastructure, or interact with services not directly accessible from the internet. While the SSRF is blind (no direct response data returned), it can facilitate mapping of internal hosts and ports, potential interaction with internal APIs or metadata services (e.g., cloud instance metadata endpoints), and limited data exfiltration through out-of-band channels. The vulnerability carries low impact to confidentiality, integrity, and availability of the vulnerable system (GitHub Advisory, M-Files Advisory).
There is no public proof-of-concept exploit code and no evidence of active in-the-wild exploitation as of the time of publication (GitHub Advisory). The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.05–0.097%, placing it in the lower percentiles for near-term exploitation likelihood. No threat actor attribution has been reported.
http://169.254.169.254/latest/meta-data/) as the target parameter.169.254.169.254), or unexpected external hosts; DNS queries from the M-Files Server to attacker-controlled domains.M-Files has released a patch in version 26.3.15818.5, which resolves this vulnerability. Organizations should upgrade M-Files Server to version 26.3.15818.5 or later as the primary remediation (M-Files Advisory, M-Files Empower). If immediate patching is not feasible, restrict network access to M-Files Server from untrusted networks and implement egress filtering to limit outbound HTTP requests from the server to only necessary internal services. Review and enforce network segmentation to reduce the blast radius of potential SSRF exploitation.
The vulnerability was assigned and disclosed by M-Files Corporation and published to the GitHub Advisory Database and NVD on April 1, 2026. It was catalogued by ENISA under EUVD-2026-17865 and noted by INCIBE-CERT. Community aggregators including VulnDB, CVEFeed, and Bluesky CVE tracking accounts picked up the disclosure shortly after publication. No significant independent researcher commentary or media coverage has been identified beyond standard vulnerability database entries (GitHub Advisory, M-Files Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."