CVE-2026-43680: Claris Filemaker Cloud
High severity, CVSS 7.2. EPSS: 0.8% chance of exploitation in the next 30 days.
A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to bypass a front-end restriction on OS Script schedule types and execute arbitrary operating system commands on the underlying host. This issue is fixed in FileMaker Cloud 2.22.0.5.
Affected products
- Claris Filemaker Cloud: before 2.22.0.5 (fixed in 2.22.0.5)
Published 2026-05-12. Last modified 2026-06-17.