CVE Vulnerabilities

CVE-2025-3086

Improper Isolation or Compartmentalization

Published: Apr 04, 2025 | Modified: Sep 30, 2025
CVSS 3.x
7.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Improper isolation of users in M-Files Server version before 25.3.14549 allows anonymous user to affect other anonymous users views and possibly cause a denial of service

Weakness

The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions.

Affected Software

Name Vendor Start Version End Version
M-files_server M-files * 25.3.14549 (excluding)

Potential Mitigations

References