Heap Buffer Overflow in FileMaker Server Database Engine by Claris
CVE-2026-86926

Currently unrated

Key Information:

Vendor

Claris

Vendor
CVE Published:
23 September 2026

What is CVE-2026-86926?

A heap buffer overflow vulnerability exists in the FileMaker Server's database engine due to improper handling in the block parsing routine. Attackers can exploit this vulnerability by sending a specially crafted .fmp12 database file, potentially leading to memory corruption. This can allow for arbitrary code execution on the affected system. It is crucial for users of FileMaker Server to ensure they are running version 26.0.3 or later to mitigate this risk.

Affected Version(s)

FileMaker Server 0 < 26.0.3

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.