Impact
An administrator who can authenticate the Open-Source LLM setup feature. The types, allowing an attacker to submit a malicious archive or script that the server processes, leading to arbitrary code execution on the host. The weakness is classified as CWE-434 and can compromise the entire system with the privileges of the FileMaker Server service.
Affected Systems
Claris FileMaker Server versions earlier than 26.0.1 are affected or any release that does not include the 26.0.1 update remain vulnerable. The fix is distributed with FileMaker Server 26.0.1 and later releases.
Risk and Exploitability
Based on the description, the attack vector requires authenticated administrator access to the internal Admin Console. The CVSS score of 4.9 and an EPSS score of <1% indicate a low but non-zero likelihood of exploitation. The vulnerability is not listed in CISA KEV. Exploitation requires an authenticated administrator account and access to the internal Admin Console, so the most likely attack vector involves an insider or a compromised administrator with network access to the server. Once the malicious file is accepted, the attacker can run commands with the service’s permissions, facilitating full system compromise.
OpenCVE Enrichment