CVE-2026-43752

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
09/07/2026
Last modified:
10/07/2026

Description

An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicious file through the Open Source LLM setup feature in the Admin Console. This vulnerability has been addressed in FileMaker Server 26.0.1.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:claris:filemaker_server:*:*:*:*:*:*:*:* 26.0.1 (excluding)