CVE-2024-10127

9.8CRITICAL

Authentication bypass condition in LDAP authentication in M-Files server versions before 24.11 supported usage of OpenLDAP configurations that allowed user authentication without a password when the L

Published: 11/20/2024Updated: 10/29/2025

Description

Authentication bypass condition in LDAP authentication in M-Files server versions before 24.11 supported usage of OpenLDAP configurations that allowed user authentication without a password when the LDAP server itself had the vulnerable configuration.

AI AnalysisPowered by AI

Affected Products

m-filesm-files_server
m-filesm-files_server

References