M-Files Vulnerability Let Attacker Capture Session Tokens of Other Active Users
Cybersecurity An information disclosure vulnerability has been identified in the M-Files Server, which allows authenticated attackers to capture and reuse session tokens from active users. This vulnerability could potentially grant unauthorized access to sensitive document management systems. Vulnerability Details The…

Cybersecurity
An information disclosure vulnerability has been identified in the M-Files Server, which allows authenticated attackers to capture and reuse session tokens from active users. This vulnerability could potentially grant unauthorized access to sensitive document management systems.
Vulnerability Details
The vulnerability, tracked as CVE-2025-13008, affects multiple versions across different release branches and has a high-severity CVSS 4.0 base score of 8.6. It exists within the M-Files Web and requires the attacker to have legitimate authentication credentials.
Once authenticated, an attacker can intercept session tokens of other actively connected users during specific client operations. These tokens can be used to impersonate legitimate users, allowing attackers to access confidential documents and potentially modify critical information.
This vulnerability could potentially grant unauthorized access to sensitive document management systems.
The flaw is classified under CWE-359 (Exposure of Private Personal Information to an Unauthorized Actor) and represents a session replay scenario per CAPEC-60. The attack requires user interaction and network accessibility, posing a practical threat in connected environments.
Affected Versions
Organizations running the following M-Files Server versions are vulnerable and should prioritize patching:
- Current Release: Vulnerable up to version 25.12.15491.7. Patched in version 25.12.15491.7.
- LTS 25.8: Vulnerable up to Before SR3. Patched in version 25.8.15085.18 (SR3).
- LTS 25.2: Vulnerable up to Before SR3. Patched in version 25.2.14524.14 (SR3).
- LTS 24.8: Vulnerable up to Before SR5. Patched in version 24.8.13981.17 (SR5).
Patching and Mitigation
M-Files has released patched versions to address this vulnerability. The company received responsible vulnerability disclosure, and no public exploits currently exist. However, due to the high-impact nature of potential attacks, organizations should not delay in applying these patches.
Security teams are advised to monitor access logs for suspicious user activity that may indicate token theft or unauthorized account use. Organizations should prioritize testing and deploying patches across all affected M-Files Server instances to mitigate this risk.




