PT-2024-8764 · M Files · M-Files Server

CVE-2024-10127

·

Published

2024-11-20

·

Updated

2026-02-23

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: M-Files Server versions prior to 24.11
Description: The issue is related to weaknesses in the authentication procedure of the M-Files Server platform, which can be exploited by a remote attacker to bypass authentication and elevate privileges. This is specifically related to the use of OpenLDAP configurations that allow user authentication without a password when the LDAP server itself has a vulnerable configuration.
Recommendations: For M-Files Server versions prior to 24.11, update to version 24.11 or later to resolve the authentication bypass condition in LDAP authentication. As a temporary workaround, consider disabling the use of OpenLDAP configurations that support anonymous binding until a patch is available. Restrict access to the LDAP authentication module to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-10379
CVE-2024-10127

Affected Products

M-Files Server