CVE Explorer
CVE-2026-0983
Denial-of-service condition in M-Files Server versions before 26.5.16015.0, before 26.2 LTS, and before 25.8 LTS SR3 allows an authenticated user to cause the MFserver process to crash
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"M-Files Server","vendor":"M-Files Corporation","versions":[{"lessThan":"26.5.16015.0","status":"affected","version":"0","versionType":"custom"},{"lessThan":"LTS 25.8.15085.24","status":"affected","version":"LTS 25.8.15085.13","versionType":"custom"},{"lessThan":"LTS 26.2.15718.10","status":"affected","version":"LTS 26.2.15718.8","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:3498173e0c6d1fd06f8c6dd8c1e5b536cf90a855b7bdf3929fd3c86cc2ad685a · sha256:0cae0958a155f517… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":7.1,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"N…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:3498173e0c6d1fd06f8c6dd8c1e5b536cf90a855b7bdf3929fd3c86cc2ad685a · sha256:0cae0958a155f517… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-1286","description":"CWE-1286 Improper validation of syntactic correctness of input","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:3498173e0c6d1fd06f8c6dd8c1e5b536cf90a855b7bdf3929fd3c86cc2ad685a · sha256:0cae0958a155f517… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"tags":["vendor-advisory"],"url":"https://empower.m-files.com/security-advisories/CVE-2026-0983"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3498173e0c6d1fd06f8c6dd8c1e5b536cf90a855b7bdf3929fd3c86cc2ad685a · sha256:0cae0958a155f517… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.