CVE-2026-86934

9.1

Claris · FileMaker Server

An authorization bypass in the FileMaker Server Web Publishing Engine permits unauthenticated access to the XML Web Publishing interface by manipulating extended privilege headers.

Executive summary

A critical authorization bypass vulnerability in Claris FileMaker Server allows unauthenticated attackers to access restricted XML publishing interfaces, posing a significant risk of data exposure.

Vulnerability

The vulnerability exists within the Web Publishing Engine, where an attacker can supply specific headers to override configuration settings that should have disabled the Custom Web Publishing with XML feature. This flaw allows unauthenticated remote attackers to interact with the XML interface, bypassing intended security controls.

Business impact

The ability for an unauthenticated actor to access the XML Web Publishing interface can lead to unauthorized data retrieval or modification, depending on the server configuration. Given the CVSS score of 9.1, this vulnerability represents a critical risk to data confidentiality and integrity, potentially enabling unauthorized access to sensitive business information hosted on FileMaker databases.

Remediation

Immediate Action: Update Claris FileMaker Server to version 26.0.3 or later to apply the necessary authorization checks.

Proactive Monitoring: Audit web server access logs for anomalous requests to the Web Publishing Engine, specifically monitoring for unusual header values or unexpected XML interface activity.

Compensating Controls: If patching is delayed, implement strict network access controls or a Web Application Firewall (WAF) to block unauthorized access to the XML publishing endpoints.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability presents a severe risk due to the potential for unauthorized data access without requiring user credentials. It is imperative that administrators prioritize the update to version 26.0.3 immediately to close the authorization bypass vector and secure the FileMaker Server environment against remote exploitation.

More Claris CVEs

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 9.1 (3.1) from cvelistV5
  4. Analyst report written
  5. Published in the daily brief critical section, early-warning entry

Sources