M-Files Vulnerability Let Attacker Capture Session Tokens of Other Active Users
ID: b535699b-87b2-5132-83ab-d11c0889cdf3
STIX ID: report--b535699b-87b2-5132-83ab-d11c0889cdf3
Feed Name: cybersecurityNews.com
Threat Score
An authenticated information-disclosure vulnerability (CVE-2025-13008) in M-Files Server allows attackers with valid credentials to capture and reuse active users' session tokens, enabling impersonation, access to confidential documents, and potential lateral movement; multiple release branches are affected and patched versions are available, CVSS 4.0 base score 8.6, and no public exploits are currently reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
