Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-86930: FileMaker Server Linux can leak memory via crafted image
CVE-2026-86930 · published 16 days ago
Summary
FileMaker Server running on Linux can be tricked into revealing parts of its own memory when a specially made picture is uploaded. An attacker could use this to see sensitive data that the server is processing. Updating to FileMaker Server version 26.0.3 resolves the issue.
What to do
- Update claris filemaker server to version 26.0.3 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| claris | filemaker server | < 26.0.3 |
Original advisory text
An out-of-bounds read vulnerability in FileMaker Server for Linux allowed an attacker uploading a specially crafted image file to a container field to disclose process memory during thumbnail gener...
An out-of-bounds read vulnerability in FileMaker Server for Linux allowed an attacker uploading a specially crafted image file to a container field to disclose process memory during thumbnail generation in FileMaker WebDirect. This vulnerability is addressed in FileMaker Server version 26.0.3.
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.1
Critical
Type
CWE-125Out-of-bounds Read
Timeline
Published23 Sep 2026
Updated7 Oct 2026
First seen23 Sep 2026
Track software like this
Free during beta