Back

HIGH

Incorrect calculation of effective permissions

Published Nov 28, 2023

Description

Under rare conditions, the effective permissions of an object might be incorrectly calculated if the object has a specific configuration of metadata-driven permissions in M-Files Server versions 23.9, 23.10, and 23.11 before 23.11.13168.7, potentially enabling unauthorized access to the object.

Affected products

Remediation

Vendor solution

Update to patched version

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner M-Files Corporation
Published Nov 28, 2023
Updated Feb 23, 2026
Reserved Nov 21, 2023
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner M-Files Corporation
Published Nov 28, 2023
Updated Feb 23, 2026
Exploited since n/a
EUVD-2023-58485