CVE-2026-18372: CSS injection in M-Files Web
Published Aug 19, 2026
·Updated
CSS injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated vault administrator to inject arbitrary CSS, affecting the web user interface displayed to other vault users.
Affected Software
1 affected component
M-Files M-Files Web<26.8.16330.2
Event History
Aug 19, 2026
CVE Published
via MITRE·11:47 AM
Data Sourced
via MITRE·11:47 AM
DescriptionWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue and who is affected?
Exploitation requires an authenticated vault administrator. The injected CSS affects the M-Files Web user interface shown to other users of that vault.
2
Which deployments need remediation?
M-Files Web versions before 26.8.16330.2 are affected. Upgrade to version 26.8.16330.2 or later.