Description
An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicious file through the Open Source LLM setup feature in the Admin Console. This vulnerability has been addressed in FileMaker Server 26.0.1.
Published: 2026-07-09
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An administrator with legitimate credentials to the Open‑Source LLM setup feature can upload a malicious archive or script which the FileMaker Server processes, leading to arbitrary code execution on the host system. The weakness is classified as CWE‑434, allowing the attacker to compromise the entire system with the privileges of the FileMaker Server service.

Affected Systems

Claris FileMaker Server versions earlier than 26.0.1, or any release that has not applied the 26.0.1 update, are affected. The fix is available in FileMaker Server 26.0.1 and later releases.

Risk and Exploitability

The attack vector requires authenticated administrator access to the internal Admin Console. With a CVSS score of 4.9 and an EPSS score of <1%, the likelihood of exploitation is low but non‑zero. The vulnerability is not listed in CISA KEV. Exploitation would typically involve an insider or a compromised administrator who can access the admin console over the network; once the malicious file is accepted, the attacker can execute commands with the service’s permissions, potentially achieving full system compromise.

Generated by OpenCVE AI on August 1, 2026 at 14:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade FileMaker Server to 26.0.1 or newer.
  • Restrict administrative console access by enforcing IP whitelists or placing the server behind a firewall.
  • Disable or restrict the Open‑Source LLM setup feature; if required, enforce strict file type validation to reject executable files.
  • Run the FileMaker Server service with the least privilege necessary.

Generated by OpenCVE AI on August 1, 2026 at 14:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Title Arbitrary Code Execution via Malicious File Upload in FileMaker Server Admin Console

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Administrator Uploads Malicious File Leading to Code Execution in FileMaker Server

Thu, 23 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Administrator Uploads Malicious File Leading to Code Execution in FileMaker Server

Tue, 21 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Authenticated Administrator Arbitrary Code Execution via LLM File Upload in FileMaker Server

Fri, 17 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Authenticated Administrator Arbitrary Code Execution via LLM File Upload in FileMaker Server

Mon, 13 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title FileMaker Server Arbitrary Code Execution via Unrestricted File Upload in Open Source LLM Setup

Sun, 12 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title FileMaker Server Arbitrary Code Execution via Unrestricted File Upload in Open Source LLM Setup

Sat, 11 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Administrative file upload enables arbitrary code execution in FileMaker Server

Fri, 10 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Administrative file upload enables arbitrary code execution in FileMaker Server

Thu, 09 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Claris
Claris filemaker Server
Vendors & Products Claris
Claris filemaker Server

Thu, 09 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-434
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Description An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicious file through the Open Source LLM setup feature in the Admin Console. This vulnerability has been addressed in FileMaker Server 26.0.1.
References

Subscriptions

Claris Filemaker Server
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-09T18:58:10.863Z

Reserved: 2026-05-01T22:46:27.815Z

Link: CVE-2026-43752

cve-icon Vulnrichment

Updated: 2026-07-09T18:46:45.500Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-09T18:16:52.160

Modified: 2026-07-10T14:34:22.677

Link: CVE-2026-43752

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T14:15:03Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type