CVE-2026-18371
M-Files Online vulnerability analysis and mitigation

Overview

CVE-2026-18371 is an HTML injection vulnerability in M-Files Web that allows an authenticated attacker to manipulate web user interface contents displayed to other users. It affects all versions of M-Files Web before 26.8.16330.2 and was published on August 19, 2026, by M-Files Corporation. The vulnerability carries a CVSS v4.0 base score of 5.1 (Medium), assigned by M-Files Corporation as the CNA (GitHub Advisory, M-Files Advisory).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation / Cross-Site Scripting), rooted in insufficient sanitization of user-supplied input before it is rendered in the M-Files Web interface. An authenticated attacker with low privileges can inject malicious HTML content that is then displayed to other users who passively view the affected interface elements, requiring no additional user interaction beyond normal browsing. No attack requirements beyond a valid account are needed, and the attack is conducted remotely over the network (GitHub Advisory, M-Files Advisory).

Impact

Successful exploitation allows an authenticated attacker to alter the web user interface content seen by other M-Files Web users, potentially enabling UI redressing, phishing within the application context, or misleading users into taking unintended actions. The integrity of both the vulnerable system and subsequent systems is rated as Low impact, with no confidentiality or availability impact identified. The vulnerability does not enable direct data exfiltration or system compromise, but could be leveraged as part of a broader social engineering or credential harvesting campaign targeting other authenticated users (GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation at the time of disclosure (Feedly). The EPSS score is 0.0, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated account, which limits the attacker pool to users with existing access to the M-Files Web environment.

Exploitation steps

  1. Obtain authenticated access: Log in to the target M-Files Web instance using a valid low-privilege user account.
  2. Identify injectable fields: Navigate through M-Files Web interface elements that accept user-supplied input and are rendered for other users (e.g., metadata fields, comments, document descriptions, or shared content areas).
  3. Craft HTML injection payload: Prepare a malicious HTML payload (e.g., <img src=x onerror=alert(1)> or a crafted <a> tag redirecting to a phishing page) designed to manipulate the UI or deceive other users.
  4. Submit the payload: Enter the crafted HTML into the vulnerable input field and save or submit it through the normal application workflow.
  5. Victim views injected content: When another authenticated user views the affected page or content, the injected HTML is rendered in their browser, potentially displaying fake UI elements, redirecting them, or executing limited client-side actions (M-Files Advisory, GitHub Advisory).

Indicators of compromise

  • Logs: M-Files Web application logs showing user-submitted content containing HTML tags (e.g., <script>, <img>, <a href=, <iframe>) in metadata or input fields that do not normally accept markup.
  • Network: Outbound requests from victim browsers to unexpected external domains shortly after viewing M-Files Web content, which may indicate injected redirect or resource-loading payloads.
  • Application: Unusual or unexpected UI elements appearing in M-Files Web for multiple users, such as fake login prompts, unexpected links, or altered interface text not matching administrative configuration.

Mitigation and workarounds

M-Files Corporation has released a patched version: update M-Files Web to version 26.8.16330.2 or later to remediate this vulnerability (M-Files Advisory). As interim measures, administrators should restrict M-Files Web access to trusted and necessary users only, and implement content security policies (CSP) at the web server or reverse proxy level to limit the impact of injected HTML. Monitoring for anomalous user-submitted content containing HTML markup is also recommended.

Additional resources


SourceThis report was generated using AI

Related M-Files Online vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-4479MEDIUM5.4
  • M-Files Online logoM-Files Online
  • cpe:2.3:a:m-files:m-files
NoYesMar 04, 2024
CVE-2023-2325MEDIUM5.4
  • M-Files Online logoM-Files Online
  • cpe:2.3:a:m-files:classic_web
NoYesOct 20, 2023
CVE-2026-18371MEDIUM5.1
  • M-Files Online logoM-Files Online
  • cpe:2.3:a:m-files:m-files_web
NoYesAug 19, 2026
CVE-2025-3087MEDIUM5.1
  • M-Files Online logoM-Files Online
  • cpe:2.3:a:m-files:m-files_web
NoYesApr 04, 2025
CVE-2026-18372MEDIUM4.8
  • M-Files Online logoM-Files Online
  • cpe:2.3:a:m-files:m-files_web
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management