
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-18372 is a CSS injection vulnerability in M-Files Web that allows an authenticated vault administrator to inject arbitrary CSS, affecting the web user interface displayed to other vault users. The vulnerability was published on August 19, 2026, and affects all M-Files Web versions before 26.8.16330.2. It carries a CVSS v4.0 base score of 4.8 (Medium), as assigned by M-Files Corporation (GitHub Advisory, M-Files Advisory).
The vulnerability is classified under CWE-79 (Improper Neutralization of Input During Web Page Generation), where user-controllable input is not properly sanitized before being rendered in the web interface (GitHub Advisory). An authenticated vault administrator can inject arbitrary CSS that is then rendered in the browsers of other vault users who visit the affected interface. Exploitation requires high privileges (vault administrator access) and passive user interaction from a victim, limiting the attack surface to insider threats or compromised administrator accounts. No public proof-of-concept or technical write-up has been identified at this time (M-Files Advisory).
Successful exploitation allows a malicious vault administrator to manipulate the visual appearance of the M-Files Web interface for other users, enabling UI-based attacks such as phishing overlays, credential harvesting prompts, or interface defacement. There is no direct confidentiality or availability impact on the vulnerable system itself; the primary risk is integrity-related, affecting the trustworthiness of the web UI presented to other vault users. The attack does not provide direct access to underlying data or system resources, but could be used as a stepping stone for social engineering attacks against other users (GitHub Advisory, M-Files Advisory).
There is no evidence of public proof-of-concept code or active in-the-wild exploitation of this vulnerability (GitHub Advisory). The EPSS score is 0.0, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for authenticated vault administrator privileges, significantly reducing the pool of potential attackers.
url() references loading external resources).Upgrade M-Files Web to version 26.8.16330.2 or later, which resolves the CSS injection vulnerability (M-Files Advisory). As an interim measure, restrict vault administrator privileges to only fully trusted personnel and audit existing administrator accounts for unauthorized access. Monitor administrative activity logs for suspicious configuration changes to UI-related settings.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."