CVE-2025-14267: Unintended temporary cached data included in a structure only copy intended to be empty of data
Published Dec 19, 2025
·Updated
Incomplete removal of sensitive information before transfer vulnerability in M-Files Corporation M-Files Server allows data leak exposure affecting versions before 25.12.15491.7
Affected Software
2 affected components
M-Files Corporation M-Files Server<25.12.15491.7
M-Files M-Files server<25.12.15491.7
Event History
Dec 19, 2025
CVE Published
via MITRE·06:15 AM
Data Sourced
via MITRE·06:15 AM
DescriptionWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-14267?
CVE-2025-14267 has been classified as a high severity vulnerability due to its potential for data leakage.
2
How do I fix CVE-2025-14267?
To resolve CVE-2025-14267, upgrade to M-Files Server version 25.12.15491.7 or later.
3
What versions of M-Files Server are affected by CVE-2025-14267?
CVE-2025-14267 affects all versions of M-Files Server prior to 25.12.15491.7.
4
What kind of data is exposed in CVE-2025-14267?
CVE-2025-14267 allows sensitive information to leak due to incomplete data removal before transfer.
5
Is there a workaround for CVE-2025-14267?
There are no documented workarounds for CVE-2025-14267; updating to a safe version is the recommended solution.