Sensitive Information Exposure in M-Files Server by M-Files Corporation
CVE-2025-14267

5.6MEDIUM

Key Information:

Vendor
CVE Published:
19 December 2025

What is CVE-2025-14267?

A vulnerability in M-Files Server allows incomplete removal of sensitive information prior to data transfer. This flaw could lead to unauthorized data exposure for users running versions before 25.12.15491.7. Organizations using the affected product are advised to upgrade to ensure protection against potential data leaks.

Affected Version(s)

M-Files Server 0 < 25.12.15491.7

References

CVSS V4

Score:
5.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-14267 : Sensitive Information Exposure in M-Files Server by M-Files Corporation