CVE-2026-43752

An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicious file through the Open Source LLM setup feature in the Admin Console. This vulnerability has been addressed in FileMaker Server 26.0.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:claris:filemaker_server:*:*:*:*:*:*:*:*

History

10 Jul 2026, 14:34

Type Values Removed Values Added
First Time Claris
Claris filemaker Server
CPE cpe:2.3:a:claris:filemaker_server:*:*:*:*:*:*:*:*
References () https://community.claris.com/en/s/article/Arbitrary-Code-Execution-Vulnerability-Addressed-in-FileMaker-Server-via-Miniforge-Installer-UploadĀ - () https://community.claris.com/en/s/article/Arbitrary-Code-Execution-Vulnerability-Addressed-in-FileMaker-Server-via-Miniforge-Installer-UploadĀ - Vendor Advisory

09 Jul 2026, 19:17

Type Values Removed Values Added
CWE CWE-434
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.9

09 Jul 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-09 18:16

Updated : 2026-07-10 14:34


NVD link : CVE-2026-43752

Mitre link : CVE-2026-43752

CVE.ORG link : CVE-2026-43752


JSON object : View

Products Affected

claris

  • filemaker_server
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type