CVE-2026-43685: Claris Filemaker Cloud

High severity, CVSS 7.2. EPSS: 0.8% chance of exploitation in the next 30 days.

A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to inject arbitrary operating system commands through unsanitized input in the External ODBC Data Source connection test feature. This issue is fixed in FileMaker Cloud 2.22.0.5.

Affected products

  • Claris Filemaker Cloud: before 2.22.0.5 (fixed in 2.22.0.5)

Published 2026-05-12. Last modified 2026-06-17.