Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-86934: FileMaker Server allows unauthorized XML publishing access

CVE-2026-86934 · published 16 days ago
Summary

The Web Publishing Engine in FileMaker Server can be tricked into opening the XML publishing interface even when the custom XML publishing feature is turned off. This could let attackers view or retrieve data they should not see. Update FileMaker Server to version 26.0.3 or newer to close the gap.

What to do
  • Update claris filemaker server to version 26.0.3 or later.
Affected software
VendorProductAffected versions
claris filemaker server < 26.0.3
Original advisory text
An authorization bypass vulnerability in the FileMaker Server Web Publishing Engine allowed requests containing an extended privilege header to bypass the disabled Custom Web Publishing with XML se...
An authorization bypass vulnerability in the FileMaker Server Web Publishing Engine allowed requests containing an extended privilege header to bypass the disabled Custom Web Publishing with XML setting and access the XML Web Publishing interface. This vulnerability is addressed in FileMaker Server version 26.0.3.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.1 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-639Authorization Bypass Through User-Controlled Key
Timeline
Published23 Sep 2026
Updated7 Oct 2026
First seen23 Sep 2026
Sources
CVE-2026-86934 · MITRE
Track software like this
Free during beta