
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-18371 is an HTML injection vulnerability in M-Files Web that allows an authenticated attacker to manipulate web user interface contents displayed to other users. It affects all versions of M-Files Web before 26.8.16330.2 and was published on August 19, 2026, by M-Files Corporation. The vulnerability carries a CVSS v4.0 base score of 5.1 (Medium), assigned by M-Files Corporation as the CNA (GitHub Advisory, M-Files Advisory).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation / Cross-Site Scripting), rooted in insufficient sanitization of user-supplied input before it is rendered in the M-Files Web interface. An authenticated attacker with low privileges can inject malicious HTML content that is then displayed to other users who passively view the affected interface elements, requiring no additional user interaction beyond normal browsing. No attack requirements beyond a valid account are needed, and the attack is conducted remotely over the network (GitHub Advisory, M-Files Advisory).
Successful exploitation allows an authenticated attacker to alter the web user interface content seen by other M-Files Web users, potentially enabling UI redressing, phishing within the application context, or misleading users into taking unintended actions. The integrity of both the vulnerable system and subsequent systems is rated as Low impact, with no confidentiality or availability impact identified. The vulnerability does not enable direct data exfiltration or system compromise, but could be leveraged as part of a broader social engineering or credential harvesting campaign targeting other authenticated users (GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation at the time of disclosure (Feedly). The EPSS score is 0.0, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated account, which limits the attacker pool to users with existing access to the M-Files Web environment.
<img src=x onerror=alert(1)> or a crafted <a> tag redirecting to a phishing page) designed to manipulate the UI or deceive other users.<script>, <img>, <a href=, <iframe>) in metadata or input fields that do not normally accept markup.M-Files Corporation has released a patched version: update M-Files Web to version 26.8.16330.2 or later to remediate this vulnerability (M-Files Advisory). As interim measures, administrators should restrict M-Files Web access to trusted and necessary users only, and implement content security policies (CSP) at the web server or reverse proxy level to limit the impact of injected HTML. Monitoring for anomalous user-submitted content containing HTML markup is also recommended.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."