Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

M-Files Vulnerability Allows Attackers to Steal Active User Session Tokens

A critical security vulnerability identified in the M-Files Server permits authenticated attackers to capture active user session tokens via the M-Files Web interface. This vulnerability facilitates identity impersonation and unauthorized access to…

A critical security vulnerability identified in the M-Files Server permits authenticated attackers to capture active user session tokens via the M-Files Web interface. This vulnerability facilitates identity impersonation and unauthorized access to sensitive information.

The flaw, designated as CVE-2025-13008 , was disclosed on Tue, Dec 19, 2025, affecting multiple versions of M-Files Server implemented across enterprise settings.

Field Details

CVE ID CVE-2025-13008

Vulnerability Type Information Disclosure / Session Token Exposure

Affected Component M-Files Web (M-Files Server)

This vulnerability facilitates identity impersonation and unauthorized access to sensitive information.
Christine Neal · Thehackingpost

Severity High

CVSS 4.0 Score 8.6

CVE-2025-13008 is an information disclosure vulnerability resulting from inadequate session token protection mechanisms in M-Files Web. Authenticated attackers can exploit this flaw to intercept and steal session tokens of other users actively using the M-Files Web interface.

The vulnerability requires specific client operations to be performed by the victim, creating an opportunity for token capture during active sessions. Using captured session tokens, attackers can impersonate legitimate users, inheriting their identity, permissions, and access rights.

Advertisement

This vulnerability affects M-Files Server installations running versions prior to 25.12.15491.7, LTS 25.8 SR3 (25.8.15085.18), LTS 25.2 SR3 (25.2.14524.14), and LTS 24.8 SR5 (24.8.13981.17). M-Files has assigned a CVSS 4.0 base score of 8.6, indicating a high severity level with significant potential for breaches of confidentiality, integrity, and availability.

The flaw falls under CWE-359 (Exposure of Private Personal Information to an Unauthorized Actor) and is mapped to CAPEC-60 (Reusing Session IDs/Session Replay).

While there have been no public exploitations of this vulnerability to date, the risk of future exploitation exists if organizations defer patching. Organizations using M-Files Server are advised to immediately upgrade to the patched versions: 25.12.15491.7 or the appropriate LTS Service Release for their deployment.

Security teams should audit M-Files Web access logs for suspicious session activity patterns and implement additional monitoring for token-based authentication anomalies until patches are fully deployed.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories