M-Files Vulnerability Allows Attackers to Steal Active User Session Tokens
A critical security vulnerability identified in the M-Files Server permits authenticated attackers to capture active user session tokens via the M-Files Web interface. This vulnerability facilitates identity impersonation and unauthorized access to…
A critical security vulnerability identified in the M-Files Server permits authenticated attackers to capture active user session tokens via the M-Files Web interface. This vulnerability facilitates identity impersonation and unauthorized access to sensitive information.
The flaw, designated as CVE-2025-13008 , was disclosed on Tue, Dec 19, 2025, affecting multiple versions of M-Files Server implemented across enterprise settings.
Field Details
CVE ID CVE-2025-13008
Vulnerability Type Information Disclosure / Session Token Exposure
Affected Component M-Files Web (M-Files Server)
This vulnerability facilitates identity impersonation and unauthorized access to sensitive information.
Severity High
CVSS 4.0 Score 8.6
CVE-2025-13008 is an information disclosure vulnerability resulting from inadequate session token protection mechanisms in M-Files Web. Authenticated attackers can exploit this flaw to intercept and steal session tokens of other users actively using the M-Files Web interface.
The vulnerability requires specific client operations to be performed by the victim, creating an opportunity for token capture during active sessions. Using captured session tokens, attackers can impersonate legitimate users, inheriting their identity, permissions, and access rights.
This vulnerability affects M-Files Server installations running versions prior to 25.12.15491.7, LTS 25.8 SR3 (25.8.15085.18), LTS 25.2 SR3 (25.2.14524.14), and LTS 24.8 SR5 (24.8.13981.17). M-Files has assigned a CVSS 4.0 base score of 8.6, indicating a high severity level with significant potential for breaches of confidentiality, integrity, and availability.
The flaw falls under CWE-359 (Exposure of Private Personal Information to an Unauthorized Actor) and is mapped to CAPEC-60 (Reusing Session IDs/Session Replay).
While there have been no public exploitations of this vulnerability to date, the risk of future exploitation exists if organizations defer patching. Organizations using M-Files Server are advised to immediately upgrade to the patched versions: 25.12.15491.7 or the appropriate LTS Service Release for their deployment.
Security teams should audit M-Files Web access logs for suspicious session activity patterns and implement additional monitoring for token-based authentication anomalies until patches are fully deployed.
Based on reporting by GBHackers.
