CVE-2026-86938

7.3

Claris · FileMaker Pro

A DLL hijacking vulnerability in the Claris FileMaker Pro installer for Windows allows a local user to achieve arbitrary code execution with elevated privileges.

Executive summary

A DLL hijacking vulnerability in the Claris FileMaker Pro installer allows a local attacker to execute arbitrary code with elevated administrator privileges, posing a significant risk to system integrity.

Vulnerability

This is a DLL hijacking vulnerability occurring within the software installer. A local, authenticated user can place a malicious DLL file in the installer directory to trigger code execution at the administrator level.

Business impact

The ability for a local user to escalate privileges to administrator status represents a severe security compromise. Successful exploitation could lead to full system takeover, unauthorized access to sensitive business data, and the potential for persistent malware installation, justifying the high CVSS score of 7.3.

Remediation

Immediate Action: Update Claris FileMaker Pro to version 26.0.3 or later to remediate the vulnerability in the installer package.

Proactive Monitoring: Monitor system logs for unauthorized file modifications or the execution of unexpected binaries in temporary installation directories.

Compensating Controls: Restrict write access to common installation and temporary directories to prevent unauthorized users from placing malicious DLL files.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for full system compromise through privilege escalation, organizations should prioritize updating all instances of FileMaker Pro to version 26.0.3. Administrators should ensure that software installation processes are performed by authorized personnel and that standard user accounts are restricted from modifying application installation paths.

More Claris CVEs

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 7.3 (3.1) from cvelistV5
  4. Analyst report written
  5. Published in the daily brief high section, early-warning entry

Sources