CVE-2026-18372
M-Files Online vulnerability analysis and mitigation

Overview

CVE-2026-18372 is a CSS injection vulnerability in M-Files Web that allows an authenticated vault administrator to inject arbitrary CSS, affecting the web user interface displayed to other vault users. The vulnerability was published on August 19, 2026, and affects all M-Files Web versions before 26.8.16330.2. It carries a CVSS v4.0 base score of 4.8 (Medium), as assigned by M-Files Corporation (GitHub Advisory, M-Files Advisory).

Technical details

The vulnerability is classified under CWE-79 (Improper Neutralization of Input During Web Page Generation), where user-controllable input is not properly sanitized before being rendered in the web interface (GitHub Advisory). An authenticated vault administrator can inject arbitrary CSS that is then rendered in the browsers of other vault users who visit the affected interface. Exploitation requires high privileges (vault administrator access) and passive user interaction from a victim, limiting the attack surface to insider threats or compromised administrator accounts. No public proof-of-concept or technical write-up has been identified at this time (M-Files Advisory).

Impact

Successful exploitation allows a malicious vault administrator to manipulate the visual appearance of the M-Files Web interface for other users, enabling UI-based attacks such as phishing overlays, credential harvesting prompts, or interface defacement. There is no direct confidentiality or availability impact on the vulnerable system itself; the primary risk is integrity-related, affecting the trustworthiness of the web UI presented to other vault users. The attack does not provide direct access to underlying data or system resources, but could be used as a stepping stone for social engineering attacks against other users (GitHub Advisory, M-Files Advisory).

Exploitability

There is no evidence of public proof-of-concept code or active in-the-wild exploitation of this vulnerability (GitHub Advisory). The EPSS score is 0.0, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for authenticated vault administrator privileges, significantly reducing the pool of potential attackers.

Exploitation steps

  1. Gain vault administrator access: Obtain or compromise credentials for an M-Files vault administrator account on an instance running M-Files Web before version 26.8.16330.2.
  2. Identify CSS injection point: Log in to the M-Files Web interface and locate administrative settings or configuration fields that accept user input rendered in the web UI without proper sanitization.
  3. Craft malicious CSS payload: Prepare an arbitrary CSS payload designed to alter the UI — for example, overlaying fake login forms, hiding legitimate UI elements, or displaying misleading content to other users.
  4. Inject the CSS: Submit the crafted CSS through the vulnerable administrative input field, causing it to be stored and subsequently rendered in the browsers of other vault users.
  5. Victim interaction: Other vault users who access the M-Files Web interface will have the injected CSS applied to their session, potentially enabling phishing or UI manipulation attacks (M-Files Advisory, GitHub Advisory).

Indicators of compromise

  • Logs: Unexpected or unusual CSS content in M-Files Web administrative configuration logs; audit log entries showing vault administrator modifications to UI-related settings.
  • Network: Unusual outbound requests from user browsers to external domains triggered by injected CSS (e.g., CSS url() references loading external resources).
  • Application Behavior: Vault users reporting unexpected visual changes to the M-Files Web interface, such as altered layouts, overlaid content, or missing UI elements.

Mitigation and workarounds

Upgrade M-Files Web to version 26.8.16330.2 or later, which resolves the CSS injection vulnerability (M-Files Advisory). As an interim measure, restrict vault administrator privileges to only fully trusted personnel and audit existing administrator accounts for unauthorized access. Monitor administrative activity logs for suspicious configuration changes to UI-related settings.

Additional resources


SourceThis report was generated using AI

Related M-Files Online vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-4479MEDIUM5.4
  • M-Files Online logoM-Files Online
  • cpe:2.3:a:m-files:m-files
NoYesMar 04, 2024
CVE-2023-2325MEDIUM5.4
  • M-Files Online logoM-Files Online
  • cpe:2.3:a:m-files:classic_web
NoYesOct 20, 2023
CVE-2026-18371MEDIUM5.1
  • M-Files Online logoM-Files Online
  • cpe:2.3:a:m-files:m-files_web
NoYesAug 19, 2026
CVE-2025-3087MEDIUM5.1
  • M-Files Online logoM-Files Online
  • cpe:2.3:a:m-files:m-files_web
NoYesApr 04, 2025
CVE-2026-18372MEDIUM4.8
  • M-Files Online logoM-Files Online
  • cpe:2.3:a:m-files:m-files_web
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management