Description
An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicious file through the Open Source LLM setup feature in the Admin Console. This vulnerability has been addressed in FileMaker Server 26.0.1.
Published: 2026-07-09
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An administrator who can authenticate the Open-Source LLM setup feature. The types, allowing an attacker to submit a malicious archive or script that the server processes, leading to arbitrary code execution on the host. The weakness is classified as CWE-434 and can compromise the entire system with the privileges of the FileMaker Server service.

Affected Systems

Claris FileMaker Server versions earlier than 26.0.1 are affected or any release that does not include the 26.0.1 update remain vulnerable. The fix is distributed with FileMaker Server 26.0.1 and later releases.

Risk and Exploitability

Based on the description, the attack vector requires authenticated administrator access to the internal Admin Console. The CVSS score of 4.9 and an EPSS score of <1% indicate a low but non-zero likelihood of exploitation. The vulnerability is not listed in CISA KEV. Exploitation requires an authenticated administrator account and access to the internal Admin Console, so the most likely attack vector involves an insider or a compromised administrator with network access to the server. Once the malicious file is accepted, the attacker can run commands with the service’s permissions, facilitating full system compromise.

Generated by OpenCVE AI on July 28, 2026 at 08:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade FileMaker Server to 26.0.1 or newer.
  • Restrict administrative console access by enforcing IP whitelists or placing the server behind a firewall.
  • Disable or restrict the Open-Source LLM setup feature; if required, enforce strict file type validation to reject executable files.
  • Run the FileMaker Server service with the least privilege necessary.

Generated by OpenCVE AI on July 28, 2026 at 08:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Administrator Uploads Malicious File Leading to Code Execution in FileMaker Server

Thu, 23 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Administrator Uploads Malicious File Leading to Code Execution in FileMaker Server

Tue, 21 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Authenticated Administrator Arbitrary Code Execution via LLM File Upload in FileMaker Server

Fri, 17 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Authenticated Administrator Arbitrary Code Execution via LLM File Upload in FileMaker Server

Mon, 13 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title FileMaker Server Arbitrary Code Execution via Unrestricted File Upload in Open Source LLM Setup

Sun, 12 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title FileMaker Server Arbitrary Code Execution via Unrestricted File Upload in Open Source LLM Setup

Sat, 11 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Administrative file upload enables arbitrary code execution in FileMaker Server

Fri, 10 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Administrative file upload enables arbitrary code execution in FileMaker Server

Thu, 09 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Claris
Claris filemaker Server
Vendors & Products Claris
Claris filemaker Server

Thu, 09 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-434
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Description An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicious file through the Open Source LLM setup feature in the Admin Console. This vulnerability has been addressed in FileMaker Server 26.0.1.
References

Subscriptions

Claris Filemaker Server
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-09T18:58:10.863Z

Reserved: 2026-05-01T22:46:27.815Z

Link: CVE-2026-43752

cve-icon Vulnrichment

Updated: 2026-07-09T18:46:45.500Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T09:00:06Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type