CVE-2026-86926

7.8

Claris · FileMaker Server

A heap buffer overflow in the FileMaker Server database engine allows memory corruption via a crafted .fmp12 file, potentially enabling arbitrary code execution.

Executive summary

A heap buffer overflow vulnerability in Claris FileMaker Server could allow an attacker to execute arbitrary code by supplying a malicious database file.

Vulnerability

This is a heap buffer overflow vulnerability located in the database engine block parsing routine. It can be triggered when the application processes a maliciously crafted .fmp12 database file, requiring user interaction to execute.

Business impact

The ability to achieve arbitrary code execution poses a severe risk to organizational data integrity and system availability. With a CVSS score of 7.8, this high-severity vulnerability could allow an attacker to compromise the server hosting the database, potentially leading to unauthorized access to sensitive business records or full system takeover.

Remediation

Immediate Action: Update Claris FileMaker Server to version 26.0.3 or later to apply the necessary security patches.

Proactive Monitoring: Review server access logs for unusual file upload activities or unexpected database engine crashes that may indicate exploitation attempts.

Compensating Controls: Restrict the ability of untrusted users to upload or import .fmp12 files into the FileMaker Server environment until the update is applied.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for arbitrary code execution, this vulnerability represents a significant security risk to the FileMaker environment. Organizations should prioritize updating to version 26.0.3 as soon as possible to neutralize this memory corruption flaw and prevent potential system compromise.

More Claris CVEs

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 7.8 (3.1) from cvelistV5
  4. Analyst report written
  5. Published in the daily brief high section, early-warning entry

Sources