Blind server-side request forgery (SSRF) vulnerability in legacy connection methods of document co-authoring features in M-Files Server before 26.3 allow an unauthenticated attacker to cause the server to send HTTP GET requests to arbitrary URLs.
Metrics
Affected Vendors & Products
References
History
Wed, 01 Apr 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Blind server-side request forgery (SSRF) vulnerability in legacy connection methods of document co-authoring features in M-Files Server before 26.3 allow an unauthenticated attacker to cause the server to send HTTP GET requests to arbitrary URLs. | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: M-Files Corporation
Published:
Updated: 2026-04-01T12:38:30.875Z
Reserved: 2026-01-14T07:38:43.377Z
Link: CVE-2026-0932
No data.
Status : Received
Published: 2026-04-01T11:15:58.263
Modified: 2026-04-01T11:15:58.263
Link: CVE-2026-0932
No data.
OpenCVE Enrichment
No data.