Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-86930: FileMaker Server Linux can leak memory via crafted image

CVE-2026-86930 · published 16 days ago
Summary

FileMaker Server running on Linux can be tricked into revealing parts of its own memory when a specially made picture is uploaded. An attacker could use this to see sensitive data that the server is processing. Updating to FileMaker Server version 26.0.3 resolves the issue.

What to do
  • Update claris filemaker server to version 26.0.3 or later.
Affected software
VendorProductAffected versions
claris filemaker server < 26.0.3
Original advisory text
An out-of-bounds read vulnerability in FileMaker Server for Linux allowed an attacker uploading a specially crafted image file to a container field to disclose process memory during thumbnail gener...
An out-of-bounds read vulnerability in FileMaker Server for Linux allowed an attacker uploading a specially crafted image file to a container field to disclose process memory during thumbnail generation in FileMaker WebDirect. This vulnerability is addressed in FileMaker Server version 26.0.3.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.1 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-125Out-of-bounds Read
Timeline
Published23 Sep 2026
Updated7 Oct 2026
First seen23 Sep 2026
Sources
CVE-2026-86930 · MITRE
Track software like this
Free during beta