CVE-2026-0932
M-Files Server vulnerability analysis and mitigation

Overview

CVE-2026-0932 is a blind Server-Side Request Forgery (SSRF) vulnerability in M-Files Server affecting legacy connection methods used by document co-authoring features. An unauthenticated remote attacker can exploit this flaw to cause the server to issue arbitrary HTTP GET requests to attacker-controlled URLs. All M-Files Server versions before 26.3.15818.5 are affected. The vulnerability was published on April 1, 2026, with a CVSS v3.1 score of 7.3 (High) and a CVSS v4.0 score of 6.9 (Medium) (GitHub Advisory, M-Files Advisory).

Technical details

The vulnerability is classified as CWE-918 (Server-Side Request Forgery), rooted in insufficient validation of URLs or request destinations within legacy connection methods of M-Files Server's document co-authoring functionality. An unauthenticated attacker can craft requests that cause the server to initiate outbound HTTP GET requests to arbitrary internal or external URLs without the server verifying the legitimacy of the destination. Because the SSRF is "blind," the attacker does not receive direct response content from the target URL, but can still infer information through timing or side-channel effects. No authentication or user interaction is required, and attack complexity is low (GitHub Advisory, M-Files Advisory).

Impact

Successful exploitation allows an unauthenticated attacker to leverage the M-Files Server as a proxy to probe internal network services, perform reconnaissance of internal infrastructure, or interact with services not directly accessible from the internet. While the SSRF is blind (no direct response data returned), it can facilitate mapping of internal hosts and ports, potential interaction with internal APIs or metadata services (e.g., cloud instance metadata endpoints), and limited data exfiltration through out-of-band channels. The vulnerability carries low impact to confidentiality, integrity, and availability of the vulnerable system (GitHub Advisory, M-Files Advisory).

Exploitability

There is no public proof-of-concept exploit code and no evidence of active in-the-wild exploitation as of the time of publication (GitHub Advisory). The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.05–0.097%, placing it in the lower percentiles for near-term exploitation likelihood. No threat actor attribution has been reported.

Exploitation steps

  1. Reconnaissance: Identify internet-facing M-Files Server instances running versions prior to 26.3.15818.5 using tools such as Shodan or Censys, searching for M-Files-specific banners or service signatures.
  2. Identify vulnerable endpoint: Locate the legacy connection method endpoints associated with M-Files Server's document co-authoring feature, which fail to validate outbound request destinations.
  3. Craft malicious request: Send an unauthenticated HTTP request to the vulnerable co-authoring endpoint, supplying an attacker-controlled URL (e.g., an internal IP address or cloud metadata endpoint such as http://169.254.169.254/latest/meta-data/) as the target parameter.
  4. Trigger SSRF: The M-Files Server processes the request and issues an HTTP GET to the attacker-specified URL, acting as a proxy.
  5. Infer results (blind): Since the SSRF is blind, use out-of-band techniques (e.g., DNS callbacks via Burp Collaborator or interactsh) to confirm that the server made the request and to gather information about reachable internal services.
  6. Internal network probing: Iterate over internal IP ranges and ports to map accessible services, leveraging response timing differences to infer open vs. closed ports (GitHub Advisory, M-Files Advisory).

Indicators of compromise

  • Network: Unusual outbound HTTP GET requests from the M-Files Server to internal IP ranges (RFC 1918 addresses), cloud metadata endpoints (e.g., 169.254.169.254), or unexpected external hosts; DNS queries from the M-Files Server to attacker-controlled domains.
  • Logs: M-Files Server access or application logs showing repeated unauthenticated requests to co-authoring legacy connection endpoints with URL parameters pointing to internal or unusual external addresses; HTTP client error logs indicating connection attempts to non-standard destinations.
  • Network: Outbound connections from the M-Files Server process to ports not typically used in normal operations (e.g., internal database ports, admin interfaces) originating from the server's IP.
  • Logs: Anomalous volume of outbound HTTP GET requests in a short time window, potentially indicating automated port scanning via SSRF.

Mitigation and workarounds

M-Files has released a patch in version 26.3.15818.5, which resolves this vulnerability. Organizations should upgrade M-Files Server to version 26.3.15818.5 or later as the primary remediation (M-Files Advisory, M-Files Empower). If immediate patching is not feasible, restrict network access to M-Files Server from untrusted networks and implement egress filtering to limit outbound HTTP requests from the server to only necessary internal services. Review and enforce network segmentation to reduce the blast radius of potential SSRF exploitation.

Community reactions

The vulnerability was assigned and disclosed by M-Files Corporation and published to the GitHub Advisory Database and NVD on April 1, 2026. It was catalogued by ENISA under EUVD-2026-17865 and noted by INCIBE-CERT. Community aggregators including VulnDB, CVEFeed, and Bluesky CVE tracking accounts picked up the disclosure shortly after publication. No significant independent researcher commentary or media coverage has been identified beyond standard vulnerability database entries (GitHub Advisory, M-Files Advisory).

Additional resources


SourceThis report was generated using AI

Related M-Files Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-13008HIGH8.6
  • M-Files Server logoM-Files Server
  • cpe:2.3:a:m-files:m-files_server
NoYesDec 19, 2025
CVE-2026-0931MEDIUM6.9
  • M-Files Server logoM-Files Server
  • cpe:2.3:a:m-files:m-files_server
NoYesAug 05, 2026
CVE-2026-0932MEDIUM6.9
  • M-Files Server logoM-Files Server
  • cpe:2.3:a:m-files:m-files_server
NoYesApr 01, 2026
CVE-2026-0663MEDIUM6.9
  • M-Files Server logoM-Files Server
  • cpe:2.3:a:m-files:m-files_server
NoYesJan 21, 2026
CVE-2025-14267MEDIUM5.6
  • M-Files Server logoM-Files Server
  • cpe:2.3:a:m-files:m-files_server
NoYesDec 19, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management