M-Files Server Improper Access Validation Vulnerability Allowing Unauthorized File Downloads

Vulnerability

A vulnerability exists in M-Files Server versions prior to 25.12, where improper access checks allow users to download files via M-Files Web Companion. This occurs despite the presence of the Print and Download Prevention module, which is intended to block such actions.

Impact

Exploitation of this vulnerability bypasses the Print and Download Prevention module, allowing unauthorized file downloads through M-Files Web Companion.

Added: Dec 18, 2025, 9:47 AM
Updated: Dec 18, 2025, 5:00 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
2.5
exploitability
4.9
remediation
0.0
relevance
1.5
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.