CVE-2025-3086: User in anonymous role could create and delete views
Published Apr 4, 2025
·Updated
Improper isolation of users in M-Files Server version before 25.3.14549 allows anonymous user to affect other anonymous users views and possibly cause a denial of service
Affected Software
2 affected components
M-Files M-Files server<25.3.14549
M-Files M-Files server<25.3.14549
Event History
Apr 4, 2025
CVE Published
via MITRE·06:37 AM
Data Sourced
via MITRE·06:37 AM
DescriptionWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-3086?
CVE-2025-3086 is classified as a medium severity vulnerability due to its potential to cause a denial of service.
2
How do I fix CVE-2025-3086?
To fix CVE-2025-3086, upgrade to M-Files Server version 25.3.14549 or later.
3
What types of users are affected by CVE-2025-3086?
CVE-2025-3086 affects anonymous users on the M-Files Server.
4
What potential impact does CVE-2025-3086 have on M-Files Server?
CVE-2025-3086 could allow one anonymous user to interfere with the views of other anonymous users and potentially cause service disruptions.
5
Is CVE-2025-3086 a zero-day vulnerability?
CVE-2025-3086 is not classified as a zero-day vulnerability since updates are available to mitigate the issue.