logo

M-Files Vulnerability Let Attacker Capture Session Tokens of Other Active Users

ID: b535699b-87b2-5132-83ab-d11c0889cdf3

STIX ID: report--b535699b-87b2-5132-83ab-d11c0889cdf3

Feed Name: cybersecurityNews.com

Threat Score
65/100

Date Published: 2025-12-27

Date Updated: 2026-04-21

Author: Abinaya

...
...

An authenticated information-disclosure vulnerability (CVE-2025-13008) in M-Files Server allows attackers with valid credentials to capture and reuse active users' session tokens, enabling impersonation, access to confidential documents, and potential lateral movement; multiple release branches are affected and patched versions are available, CVSS 4.0 base score 8.6, and no public exploits are currently reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.