CVE-2026-86930
9.1Claris · FileMaker Server
A critical out-of-bounds read vulnerability in Claris FileMaker Server for Linux allows unauthenticated attackers to disclose process memory via crafted image files in FileMaker WebDirect.
Executive summary
A critical out-of-bounds read vulnerability in Claris FileMaker Server for Linux poses a severe risk of information disclosure and potential denial of service.
Vulnerability
This is an out-of-bounds read vulnerability triggered during thumbnail generation in FileMaker WebDirect. An unauthenticated attacker can exploit this by uploading a specially crafted image file to a container field, leading to the disclosure of process memory.
Business impact
Successful exploitation allows an unauthenticated attacker to read sensitive process memory, which may contain credentials, session tokens, or other confidential information. Given the CVSS score of 9.1, this represents a critical risk to data confidentiality and system integrity. Failure to remediate could result in significant data breaches and unauthorized access to internal FileMaker database environments.
Remediation
Immediate Action: Update Claris FileMaker Server to version 26.0.3 or later immediately to resolve the underlying out-of-bounds read flaw.
Proactive Monitoring: Review web server and FileMaker application logs for unusual image upload patterns or repeated attempts to trigger thumbnail generation processes.
Compensating Controls: Implement strict input validation or file type restrictions on container fields via a Web Application Firewall (WAF) to block malicious or malformed image files from reaching the server.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability presents a critical threat due to its unauthenticated attack vector and the potential for memory disclosure. Security teams should prioritize the update of all FileMaker Server instances to version 26.0.3. If immediate patching is not feasible, restrict access to the WebDirect interface to trusted networks until the update can be applied.
More Claris CVEs
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 9.1 (3.1) from cvelistV5
- Analyst report written
- Published in the daily brief critical section, early-warning entry