High severity7.3NVD Advisory· Published Apr 1, 2026· Updated Apr 2, 2026
CVE-2026-0932
CVE-2026-0932
Description
Blind server-side request forgery (SSRF) vulnerability in legacy connection methods of document co-authoring features in M-Files Server before 26.3 allow an unauthenticated attacker to cause the server to send HTTP GET requests to arbitrary URLs.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- empower.m-files.com/security-advisories/CVE-2026-0932nvdVendor Advisory
- product.m-files.com/security-advisories/cve-2026-0932/nvdVendor Advisory
News mentions
0No linked articles in our index yet.