An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicious file through the Open Source LLM setup feature in the Admin Console. This vulnerability has been addressed in FileMaker Server 26.0.1.

Project Subscriptions

Vendors Products
Filemaker Server Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 23 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Administrator Uploads Malicious File Leading to Code Execution in FileMaker Server

Tue, 21 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Authenticated Administrator Arbitrary Code Execution via LLM File Upload in FileMaker Server

Fri, 17 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Authenticated Administrator Arbitrary Code Execution via LLM File Upload in FileMaker Server

Mon, 13 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title FileMaker Server Arbitrary Code Execution via Unrestricted File Upload in Open Source LLM Setup

Sun, 12 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title FileMaker Server Arbitrary Code Execution via Unrestricted File Upload in Open Source LLM Setup

Sat, 11 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Administrative file upload enables arbitrary code execution in FileMaker Server

Fri, 10 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Administrative file upload enables arbitrary code execution in FileMaker Server

Thu, 09 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Claris
Claris filemaker Server
Vendors & Products Claris
Claris filemaker Server

Thu, 09 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-434
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Description An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicious file through the Open Source LLM setup feature in the Admin Console. This vulnerability has been addressed in FileMaker Server 26.0.1.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-09T18:58:10.863Z

Reserved: 2026-05-01T22:46:27.815Z

Link: CVE-2026-43752

cve-icon Vulnrichment

Updated: 2026-07-09T18:46:45.500Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-23T09:45:04Z

Weaknesses