CVE-2026-43685

A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to inject arbitrary operating system commands through unsanitized input in the External ODBC Data Source connection test feature. This issue is fixed in FileMaker Cloud 2.22.0.5.
Configurations

Configuration 1 (hide)

cpe:2.3:a:claris:filemaker_cloud:*:*:*:*:*:*:*:*

History

14 May 2026, 13:52

Type Values Removed Values Added
First Time Claris filemaker Cloud
Claris
References () https://support.claris.com/s/answerview?anum=000049154&language=en_US - () https://support.claris.com/s/answerview?anum=000049154&language=en_US - Vendor Advisory
CPE cpe:2.3:a:claris:filemaker_cloud:*:*:*:*:*:*:*:*

13 May 2026, 14:49

Type Values Removed Values Added
CWE CWE-78
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2

12 May 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-12 23:16

Updated : 2026-05-14 13:52


NVD link : CVE-2026-43685

Mitre link : CVE-2026-43685

CVE.ORG link : CVE-2026-43685


JSON object : View

Products Affected

claris

  • filemaker_cloud
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')