What is CVE-2026-18372?
This vulnerability in M-Files Web allows an authenticated vault administrator to inject arbitrary CSS, impacting the web user interface displayed to other users. To mitigate this issue, it is recommended to update M-Files Web to version 26.8.16330.2 or later.
Azərbaycanca: Bu zəiflik M-Files Web platformasında autentifikasiya olunmuş vault administratoruna digər istifadəçilərin gördüyü veb interfeysə ixtiyari CSS kodu inyeksiya etməyə imkan verir. Bütün istifadəçilərə təsir edə biləcək bu təhlükədən qorunmaq üçün M-Files Web tətbiqinizi ən azı 26.8.16330.2 versiyasına yeniləməyiniz tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: M-Files
FAQ2
Which privileged role in M-Files Web can exploit CVE-2026-18372?
This vulnerability in M-Files Web can be exploited by an authenticated vault administrator.
To which version should M-Files Web be updated to mitigate CVE-2026-18372?
It is recommended to update M-Files Web to version 26.8.16330.2 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.