CVE-2026-18371: HTML injection in M-Files Web
Published Aug 19, 2026
·Updated
HTML injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated attacker to affect web user interface contents displayed to other users.
Affected Software
1 affected component
M-Files M-Files Web<26.8.16330.2
Event History
Aug 19, 2026
CVE Published
via MITRE·11:46 AM
Data Sourced
via MITRE·11:46 AM
DescriptionWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker must be authenticated to M-Files Web. The issue can affect other users when they view web interface content influenced by the attacker.
2
Which versions should be prioritized for remediation?
M-Files Web versions before 26.8.16330.2 are affected. Upgrade to 26.8.16330.2 or a later version.