Impact
An administrator with legitimate credentials to the Open‑Source LLM setup feature can upload a malicious archive or script which the FileMaker Server processes, leading to arbitrary code execution on the host system. The weakness is classified as CWE‑434, allowing the attacker to compromise the entire system with the privileges of the FileMaker Server service.
Affected Systems
Claris FileMaker Server versions earlier than 26.0.1, or any release that has not applied the 26.0.1 update, are affected. The fix is available in FileMaker Server 26.0.1 and later releases.
Risk and Exploitability
The attack vector requires authenticated administrator access to the internal Admin Console. With a CVSS score of 4.9 and an EPSS score of <1%, the likelihood of exploitation is low but non‑zero. The vulnerability is not listed in CISA KEV. Exploitation would typically involve an insider or a compromised administrator who can access the admin console over the network; once the malicious file is accepted, the attacker can execute commands with the service’s permissions, potentially achieving full system compromise.
OpenCVE Enrichment