CVE-2026-43752: Claris Filemaker Server

Medium severity, CVSS 4.9. EPSS: 0.5% chance of exploitation in the next 30 days.

An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicious file through the Open Source LLM setup feature in the Admin Console. This vulnerability has been addressed in FileMaker Server 26.0.1.

Affected products

  • Claris Filemaker Server: before 26.0.1 (fixed in 26.0.1)

Published 2026-07-09. Last modified 2026-07-10.