Critical severity9.8NVD Advisory· Published Nov 20, 2024· Updated Jun 17, 2026
CVE-2024-10127
CVE-2024-10127
Description
Authentication bypass condition in LDAP authentication in M-Files server versions before 24.11 supported usage of OpenLDAP configurations that allowed user authentication without a password when the LDAP server itself had the vulnerable configuration.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- M-Files Corporation/M-Files Serverv5Range: 0
<24.11+ 2 more
- (no CPE)range: <24.11
- cpe:2.3:a:m-files:m-files_server:*:*:*:*:lts:*:*:*range: <24.8.13981.13
- cpe:2.3:a:m-files:m-files_server:*:*:*:*:-:*:*:*range: <24.11
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.