CVE-2025-14318: Improper access validation in M-Files Server
Published Dec 18, 2025
·Updated
Improper access checks in M-Files Server before 25.12.15491.7 allows users to download files through M-Files Web using Web Companion despite Print and Download Prevention module being enabled.
Affected Software
2 affected components
M-Files M-Files server<25.12.15491.7
M-Files M-Files server<25.12.15491.7
Remediation
Information
Update to the latest version.
Event History
Dec 18, 2025
CVE Published
via MITRE·07:32 AM
Data Sourced
via MITRE·07:32 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-14318?
CVE-2025-14318 is classified as a moderate severity vulnerability due to improper access checks in M-Files Server.
2
How do I fix CVE-2025-14318?
To fix CVE-2025-14318, upgrade M-Files Server to version 25.12 or later.
3
What does CVE-2025-14318 allow unauthorized users to do?
CVE-2025-14318 allows unauthorized users to download files through M-Files Web despite restrictions from the Print and Download Prevention module.
4
Which versions of M-Files Server are affected by CVE-2025-14318?
M-Files Server versions prior to 25.12 are affected by CVE-2025-14318.
5
Is there a workaround for CVE-2025-14318?
No reliable workaround exists for CVE-2025-14318; the only solution is to upgrade to the latest version.