What is CVE-2026-18371?
CVE-2026-18371 is an HTML injection vulnerability in M-Files Web before version 26.8.16330.2, allowing an authenticated attacker to alter the web UI content displayed to other users. This could lead to user deception or exposure to malicious content. Upgrading M-Files Web to the latest version is recommended.
Azərbaycanca: CVE-2026-18371, 26.8.16330.2 versiyasından əvvəlki M-Files Web-də autentifikasiya olunmuş hücumçunun digər istifadəçilərə göstərilən veb interfeys məzmununu dəyişdirməsinə imkan verən HTML injection zəifliyidir. Bu, istifadəçilərin aldadılmasına və ya zərərli məzmuna məruz qalmasına səbəb ola bilər. M-Files Web tətbiqini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: M-Files
FAQ2
Which versions of M-Files Web are affected by CVE-2026-18371?
This HTML injection vulnerability affects M-Files Web versions before 26.8.16330.2.
What can an attacker do by exploiting CVE-2026-18371?
An authenticated attacker can alter the web UI content displayed to other users, which could lead to user deception or exposure to malicious content.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.