CVE-2025-46296

An authorization bypass vulnerability in FileMaker Server Admin Console allowed administrator roles with minimal privileges to access administrative features such as viewing license details and downloading application logs. This vulnerability has been fully addressed in FileMaker Server 22.0.4.
Configurations

Configuration 1 (hide)

cpe:2.3:a:claris:filemaker_server:*:*:*:*:*:*:*:*

History

23 Dec 2025, 14:45

Type Values Removed Values Added
CPE cpe:2.3:a:claris:filemaker_server:*:*:*:*:*:*:*:*
First Time Claris
Claris filemaker Server
References () https://support.claris.com/s/answerview?anum=000049056&language=en_US - () https://support.claris.com/s/answerview?anum=000049056&language=en_US - Vendor Advisory

16 Dec 2025, 20:15

Type Values Removed Values Added
CWE CWE-285
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

16 Dec 2025, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-16 18:16

Updated : 2025-12-23 14:45


NVD link : CVE-2025-46296

Mitre link : CVE-2025-46296

CVE.ORG link : CVE-2025-46296


JSON object : View

Products Affected

claris

  • filemaker_server
CWE
CWE-285

Improper Authorization