A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to inject arbitrary operating system commands through unsanitized input in the External ODBC Data Source connection test feature. This issue is fixed in FileMaker Cloud 2.22.0.5.
References
| Link | Resource |
|---|---|
| https://support.claris.com/s/answerview?anum=000049154&language=en_US | Vendor Advisory |
Configurations
History
14 May 2026, 13:52
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Claris filemaker Cloud
Claris |
|
| References | () https://support.claris.com/s/answerview?anum=000049154&language=en_US - Vendor Advisory | |
| CPE | cpe:2.3:a:claris:filemaker_cloud:*:*:*:*:*:*:*:* |
13 May 2026, 14:49
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-78 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.2 |
12 May 2026, 23:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-12 23:16
Updated : 2026-05-14 13:52
NVD link : CVE-2026-43685
Mitre link : CVE-2026-43685
CVE.ORG link : CVE-2026-43685
JSON object : View
Products Affected
claris
- filemaker_cloud
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
