CVE-2026-0663: Denial of Service condition in M-Files Server
Denial-of-service vulnerability in M-Files Server versions before 26.1.15632.3 allows an authenticated attacker with vault administrator privileges to crash the M-Files Server process by calling a vulnerable API endpoint.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0663?
CVE-2026-0663 is a denial of service vulnerability that can lead to the M-Files Server crashing.
How do I fix CVE-2026-0663?
To mitigate CVE-2026-0663, upgrade M-Files Server to version 26.1.15632.3 or later.
Who is affected by CVE-2026-0663?
CVE-2026-0663 affects M-Files Server versions prior to 26.1.15632.3 when accessed by authenticated users with vault administrator privileges.
What kind of attack does CVE-2026-0663 enable?
CVE-2026-0663 enables authenticated attackers to exploit a vulnerable API endpoint, causing a denial of service.
Is CVE-2026-0663 a remote or local vulnerability?
CVE-2026-0663 is a local vulnerability that requires authenticated access to the M-Files Server to exploit.