An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicious file through the Open Source LLM setup feature in the Admin Console. This vulnerability has been addressed in FileMaker Server 26.0.1.
References
Configurations
History
No history.
Information
Published : 2026-07-09 18:16
Updated : 2026-07-10 14:34
NVD link : CVE-2026-43752
Mitre link : CVE-2026-43752
CVE.ORG link : CVE-2026-43752
JSON object : View
Products Affected
claris
- filemaker_server
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
